Junglewise Threat Intelligence

CVE-2026-75766: Adobe Substance3D Painter heap buffer overflow

CVE-2026-75766 · Severity: high · CVSS 7.8 · Published 2026-08-25

Technologies: Adobe Substance3D Painter, Adobe Substance 3d Painter. Vendors: Adobe.

Executive brief

Adobe Substance3D Painter is a 3D art and design application used by creative professionals. A heap buffer overflow vulnerability allows an attacker to execute arbitrary code on a victim's machine if they can trick the user into opening a malicious file, potentially compromising the artist's work, system integrity, and credentials.

Technical details

The vulnerability is a heap-based buffer overflow in Adobe Substance3D Painter that can be triggered by parsing a specially crafted file. An attacker with no special privileges can exploit this by crafting a malicious file and distributing it to users. The attack requires user interaction (opening the malicious file), but upon successful exploitation, the attacker can achieve arbitrary code execution in the context of the current user. No details on affected versions or patch status are available from the provided advisory references.

Affected products

  • Adobe Substance3D Painter <UNKNOWN>

Timeline

  • 2026-08-25: disclosed

References

Related threats