CVE-2026-48428: Substance3D - Designer | Heap-based Buffer Overflow (CWE-122)
Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
Who is most exposed to this issue?
Users of Adobe Substance3D Designer who can be persuaded to open an attacker-controlled malicious file are exposed. Successful exploitation runs code in the context of the current user.
What does an attacker need to exploit the vulnerability?
The attacker needs a victim to open a malicious file. The provided information does not indicate that authentication or prior access to the victim's system is required.
What can be done while a patch is not immediately available?
Avoid opening untrusted or unsolicited files in Substance3D Designer, especially files received through email, downloads, or other unverified sources. Because exploitation requires user interaction, restricting malicious-file handling reduces exposure.