Junglewise Threat Intelligence

CVE-2026-48433: Adobe Substance3D Designer heap buffer overflow

CVE-2026-48433 · Severity: high · CVSS 7.8 · Published 2026-08-25

Technologies: Adobe Substance 3d Designer, Adobe Substance3D Designer. Vendors: Adobe.

Executive brief

Adobe Substance3D Designer is a 3D design and modeling tool used by creative professionals to develop digital assets. A heap buffer overflow vulnerability in the application could allow an attacker to execute arbitrary code with the privileges of the user running the application, if the victim opens a malicious design file.

Technical details

The vulnerability is a heap-based buffer overflow in Adobe Substance3D Designer that can be triggered by parsing specially crafted input within a design file. The attack requires user interaction—specifically, the victim must open a malicious file in the application. Successful exploitation allows an attacker to achieve arbitrary code execution in the context of the current user. The vulnerability is not known to be actively exploited in the wild.

Affected products

  • Adobe Substance3D Designer

Timeline

  • 2026-08-25: disclosed

References

Related threats