
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34674 is a Heap-based Buffer Overflow vulnerability in Adobe Substance 3D Sampler versions 5.1.3 and earlier that can result in arbitrary code execution in the context of the current user. The vulnerability was disclosed by Adobe on May 12, 2026, and published to the NVD on August 27, 2026. It carries a CVSS v3.1 base score of 7.8 (High), requiring local access and user interaction but no special privileges (Adobe Advisory, GitHub Advisory).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow), occurring when the application processes a specially crafted malicious file, causing a write operation to overflow a heap-allocated buffer. The attack vector is local, requiring no privileges, but does require a victim to open a malicious file — a social engineering precondition. The associated CAPEC pattern is CAPEC-92 (Forced Integer Overflow), suggesting the overflow may be triggered via malformed size or length values in a parsed file format (GitHub Advisory, Adobe Advisory).
Successful exploitation results in arbitrary code execution with the privileges of the current user, yielding high impact to confidentiality, integrity, and availability. An attacker who tricks a victim into opening a malicious file could fully compromise the affected workstation, access sensitive data, install malware, or pivot to other systems on the network. The scope is unchanged, meaning the impact is contained to the security context of the vulnerable application, but full user-level compromise is achievable (Adobe Advisory, GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the latest update (Adobe Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD's SSVC assessment confirms exploitation status as "none" and the vulnerability as non-automatable. The EPSS score is approximately 0.238%, placing it in the 15th percentile for exploitation likelihood within 30 days (GitHub Advisory).
cmd.exe, powershell.exe, bash, curl, or network-connecting processes)..sbs, .sbsar, or other Sampler-format files from untrusted sources.Adobe has released version 6.0 of Substance 3D Sampler as the patched release; users should update immediately from version 5.1.3 or earlier to 6.0 or later (Adobe Advisory). As interim mitigations, organizations should restrict access to untrusted files, educate users about the risks of opening files from unknown sources, and consider disabling or removing the application if patching cannot be applied promptly. Detection coverage is available via Qualys (detection ID 387310) and Nessus (plugin ID 314924).
The CIS (Center for Internet Security) issued an advisory noting multiple Adobe vulnerabilities in May 2026 that could allow arbitrary code execution, including this issue (CIS Advisory). CISA referenced the vulnerability in its weekly bulletin (SB26-243). No significant independent researcher commentary or social media discussion has been identified for this specific CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."