Junglewise Threat Intelligence

CVE-2026-83963: Adobe Substance3D Modeler out-of-bounds write

CVE-2026-83963 · Severity: high · CVSS 7.8 · Published 2026-09-22

Technologies: Adobe Substance3D Modeler, Adobe Substance 3d Modeler. Vendors: Adobe.

Executive brief

Adobe Substance3D Modeler is a 3D design and modeling tool used by creative professionals. An out-of-bounds write vulnerability allows attackers to execute arbitrary code with the privileges of the current user by tricking a victim into opening a specially crafted file. This could allow an attacker to compromise a designer's workstation and access sensitive design files or escalate privileges.

Technical details

The vulnerability is an out-of-bounds write in Substance3D Modeler that can be triggered when processing a malicious file. Exploitation requires user interaction to open the crafted file, and results in arbitrary code execution in the context of the logged-in user. A patch is available from Adobe.

Affected products

  • Adobe Substance3D Modeler <UNKNOWN>

Timeline

  • 2026-09-22: disclosed

References

Related threats