Heap-based Buffer Overflow in Substance3D Sampler by Adobe
CVE-2026-34674

7.8HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
27 August 2026

What is CVE-2026-34674?

The Substance3D Sampler software from Adobe is susceptible to a heap-based buffer overflow vulnerability. This issue permits arbitrary code execution when a user interacts with a specially crafted malicious file. Successful exploitation hinges on user action, requiring a victim to open the compromised file. This vulnerability poses significant risk as it operates in the context of the current user, potentially allowing an attacker to execute malicious code within the user's environment.

Affected Version(s)

Adobe Substance 3D Sampler 0 <= 5.1.3

Adobe Substance 3D Sampler 0 <= 5.1.3

Adobe Substance 3D Sampler 6.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.