Heap-based Buffer Overflow in Substance3D Sampler by Adobe
CVE-2026-83959

7.8HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
3 September 2026

What is CVE-2026-83959?

The Substance3D Sampler by Adobe is susceptible to a heap-based buffer overflow vulnerability that may allow attackers to execute arbitrary code within the context of the currently logged in user. This exploit necessitates user interaction; specifically, a victim must open a specially crafted malicious file for the vulnerability to be triggered. Users of the Substance3D Sampler should remain vigilant and update their software to mitigate potential risks.

Affected Version(s)

Adobe Substance 3D Sampler 0 <= 6.0.1

Adobe Substance 3D Sampler 6.0.3

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.