CVE-2026-81998: Substance3D - Modeler | Out-of-bounds Write (CWE-787)
Published Sep 22, 2026
·Updated
Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
1 affected component
Adobe Substance 3d Modeler
Event History
Sep 22, 2026
CVE Published
via MITRE·06:57 PM
Data Sourced
via MITRE·06:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What must an attacker do to exploit this issue?
The attacker must persuade a victim to open a malicious file in Substance3D - Modeler. Exploitation occurs in the context of the current user.
2
Who is exposed to the greatest impact?
Users running Substance3D - Modeler who open attacker-supplied or untrusted files are exposed. Successful exploitation could allow arbitrary code execution with the permissions of the affected user.