Executive brief
Substance3D Painter is a 3D design and texturing tool used by artists and designers for creating digital content. A vulnerability in the application's library search path allows attackers to execute arbitrary code on a user's system if the victim opens a malicious file, potentially compromising the designer's computer and any work in progress.
Technical details
The vulnerability is an untrusted search path issue in Substance3D Painter where the application loads libraries from directories that an attacker can control or influence. This allows arbitrary code execution in the context of the current user. The attack requires user interaction—specifically, the victim must open a malicious file crafted to exploit the search path behavior. An attacker can achieve code execution with the privileges of the logged-in user. The vulnerability was assigned CVE-2026-75768 with a CVSS score of 7.8 (high severity).
Affected products
- Adobe Substance3D Painter
Timeline
- 2026-08-25: disclosed