Heap-based Buffer Overflow in Substance3D Sampler by Adobe
CVE-2026-48424

7.8HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
25 August 2026

What is CVE-2026-48424?

Adobe Substance3D Sampler is susceptible to a Heap-based Buffer Overflow vulnerability that can be exploited to execute arbitrary code within the user's context. This vulnerability necessitates user action; specifically, an end user must open a crafted malicious file for exploitation to occur. Successful exploitation could allow an attacker to gain unauthorized control over the affected system. Users are advised to remain vigilant and avoid opening suspicious files to mitigate risks associated with this vulnerability.

Affected Version(s)

Adobe Substance 3D Sampler 0 <= 6.0.1

Adobe Substance 3D Sampler 0 <= 6.0.1

Adobe Substance 3D Sampler 6.0.3

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.