Junglewise Threat Intelligence

CVE-2026-75767: Adobe Substance3D Painter heap buffer overflow

CVE-2026-75767 · Severity: high · CVSS 7.8 · Published 2026-08-25

Technologies: Adobe Substance3D Painter, Adobe Substance 3d Painter. Vendors: Adobe.

Executive brief

Substance3D Painter is a professional 3D design and texturing tool used by artists and designers to create digital assets. A heap buffer overflow vulnerability could allow an attacker to execute arbitrary code with the privileges of the user running the application if they trick a user into opening a malicious file. This could lead to unauthorized access to sensitive design files, system compromise, or data theft.

Technical details

The vulnerability is a heap-based buffer overflow in Adobe Substance3D Painter that can be triggered by opening a specially crafted malicious file. The vulnerability class is CWE-122 (heap-based buffer overflow), and exploitation requires user interaction (opening a malicious file). An attacker can achieve arbitrary code execution in the context of the current user. The attack vector is local, requiring the user to manually open the malicious file. A patch is expected to be available through Adobe's security advisory APSB26-129.

Affected products

  • Adobe Substance3D Painter

Timeline

  • 2026-08-25: disclosed

References

Related threats