CVE-2026-48306: Substance3D - Sampler | Out-of-bounds Write (CWE-787)
Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Substance3D - Samplerfrom your environment.If Substance3D Sampler is not required, uninstall it from impacted systems to eliminate the vulnerability exposure.
- Compensating control
Reduce exposure by blocking or scanning untrusted files before they reach users: enforce email/attachment filtering, use sandboxing or detonation chambers for suspicious files, and ensure endpoint security (AV/EDR) inspects files before allowing them to be opened.
- Operational
Instruct users not to open files from untrusted or unknown sources, and provide awareness that exploitation requires user interaction (opening a malicious file).
- Operational
Monitor vendor advisories for Substance3D Sampler and apply any vendor-supplied updates or patches as soon as they are released.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48306?
CVE-2026-48306 has a high severity rating of 7.8.
How do I fix CVE-2026-48306?
To fix CVE-2026-48306, update Adobe Substance 3D Sampler to version 6.0.1 or later.
What type of vulnerability is CVE-2026-48306?
CVE-2026-48306 is an out-of-bounds write vulnerability classified under CWE-787.
What could exploitation of CVE-2026-48306 lead to?
Exploitation of CVE-2026-48306 could potentially result in arbitrary code execution in the context of the current user.
Does CVE-2026-48306 require user interaction to exploit?
Yes, exploitation of CVE-2026-48306 requires user interaction, specifically the opening of a malicious file.