Junglewise Threat Intelligence

CVE-2026-48431: Adobe Substance 3D Designer heap buffer overflow

CVE-2026-48431 · Severity: high · CVSS 7.8 · Published 2026-08-25

Technologies: Adobe Substance 3d Designer. Vendors: Adobe.

Executive brief

Adobe Substance 3D Designer is a professional 3D modeling and texturing software used by graphics professionals and artists. A heap buffer overflow vulnerability in this application could allow attackers to execute arbitrary code on a user's machine if they trick them into opening a malicious file, potentially compromising sensitive project data and system integrity.

Technical details

This vulnerability is a heap-based buffer overflow in Adobe Substance 3D Designer that permits arbitrary code execution within the context of the user running the application. The vulnerability requires user interaction, specifically opening a crafted malicious file. This is a classic memory corruption bug where inadequate bounds checking on heap-allocated buffers allows an attacker-controlled input to overflow and corrupt adjacent memory, enabling code execution. No public exploit code is currently known to be circulating in the wild.

Affected products

  • Adobe Substance 3D Designer

Timeline

  • 2026-08-25: disclosed

References

Related threats