Executive brief
Adobe Substance3D Painter, a professional 3D painting and texturing tool used by digital artists and game developers, is vulnerable to a heap buffer overflow that could allow attackers to execute arbitrary code on a user's computer. An attacker would need to trick a user into opening a specially crafted malicious file, after which the application could be compromised, potentially leading to data theft or system compromise.
Technical details
This is a heap-based buffer overflow vulnerability in Adobe Substance3D Painter that can be triggered when processing specially crafted input files. The vulnerability requires user interaction—a victim must open a malicious file—making it a user-initiated attack vector. Successful exploitation allows arbitrary code execution in the context of the current user, granting an attacker the same privileges as the logged-in user. The vulnerability was reported with a CVSS v3.1 score of 7.8 (high severity) and no active exploitation in the wild at time of publication. Patches are likely available through Adobe's security advisory APSB26-129.
Affected products
- Adobe Substance3D Painter
Timeline
- 2026-08-25: disclosed: CVE-2026-75750 published
- 2026-08-25: advisory: Adobe APSB26-129 advisory released