Heap-based Buffer Overflow Vulnerability in Substance3D Designer by Adobe
CVE-2026-48428

7.8HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
25 August 2026

What is CVE-2026-48428?

Substance3D Designer by Adobe is susceptible to a Heap-based Buffer Overflow vulnerability, which can lead to arbitrary code execution under the context of the current user. The exploitation of this vulnerability requires user interaction, as the victim must open a specially crafted malicious file. It's crucial for users of Substance3D Designer to remain vigilant and update to the latest versions to mitigate potential risks.

Affected Version(s)

Adobe Substance 3D Designer 0 <= 16.0.4

Adobe Substance 3D Designer 0 <= 16.0.4

Adobe Substance 3D Designer 16.0.5

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.