Junglewise Threat Intelligence

CVE-2026-75769: Adobe Substance 3D Painter heap-based buffer overflow

CVE-2026-75769 · Severity: high · CVSS 7.8 · Published 2026-08-25

Technologies: Adobe Substance 3d Painter. Vendors: Adobe.

Executive brief

Adobe Substance 3D Painter is a 3D design and painting application used by creative professionals. A heap-based buffer overflow vulnerability in the application could allow an attacker to execute arbitrary code on a user's system if the user opens a specially crafted malicious file. This could lead to data theft, system compromise, or malware installation on affected workstations.

Technical details

Substance 3D Painter is affected by a heap-based buffer overflow vulnerability that can result in arbitrary code execution with the privileges of the currently logged-in user. The vulnerability is triggered through file handling when a victim opens a maliciously crafted file in the application. User interaction is required for exploitation, as the attacker cannot trigger the flaw remotely without the user's action. The vulnerability allows an attacker to overwrite heap memory and potentially achieve code execution in the context of the application process. Adobe has assigned this issue CVE-2026-75769 with a CVSS score of 7.8 (high severity).

Affected products

  • Adobe Substance 3D Painter

Timeline

  • 2026-08-25: disclosed

References

Related threats