Junglewise Threat Intelligence

CVE-2026-48429: Adobe Substance3D Designer NULL pointer dereference

CVE-2026-48429 · Severity: medium · CVSS 5.5 · Published 2026-08-25

Technologies: Adobe Substance 3d Designer, Adobe Substance3D Designer. Vendors: Adobe.

Executive brief

Adobe Substance3D Designer is a professional 3D design and rendering tool. A NULL pointer dereference vulnerability allows an attacker to crash the application by tricking a user into opening a specially crafted malicious file, causing a denial-of-service condition that disrupts the designer's work.

Technical details

The vulnerability is a NULL pointer dereference flaw in Adobe Substance3D Designer that triggers an application crash. The attack requires user interaction—specifically, a victim must open a malicious file crafted to trigger the NULL pointer condition. The vulnerability is classified as a denial-of-service issue, preventing legitimate use of the application. No remote or network exploitation is possible; the attack is local and requires social engineering or file delivery to the victim.

Affected products

  • Adobe Substance3D Designer

Timeline

  • 2026-08-25: disclosed

References

Related threats