Executive brief
Substance3D Painter is a professional 3D design and texturing tool used by artists and designers to create digital assets. A heap buffer overflow vulnerability could allow an attacker to execute arbitrary code with the privileges of the user running the application if they trick a user into opening a malicious file. This could lead to unauthorized access to sensitive design files, system compromise, or data theft.
Technical details
The vulnerability is a heap-based buffer overflow in Adobe Substance3D Painter that can be triggered by opening a specially crafted malicious file. The vulnerability class is CWE-122 (heap-based buffer overflow), and exploitation requires user interaction (opening a malicious file). An attacker can achieve arbitrary code execution in the context of the current user. The attack vector is local, requiring the user to manually open the malicious file. A patch is expected to be available through Adobe's security advisory APSB26-129.
Affected products
- Adobe Substance3D Painter
Timeline
- 2026-08-25: disclosed