
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34710 is an out-of-bounds write vulnerability (CWE-787) in Adobe Substance 3D Sampler versions 6.0.0 and earlier that can result in arbitrary code execution in the context of the current user. The vulnerability was disclosed and patched on June 9, 2026, as part of Adobe's June 2026 security update cycle. It carries a CVSS v3.1 base score of 7.8 (High), with exploitation requiring local access and user interaction (Adobe Advisory, GitHub Advisory).
The root cause is an out-of-bounds write (CWE-787), where the application writes data beyond the bounds of an allocated buffer when processing a specially crafted file. The attack vector is local, requiring no privileges but necessitating that a victim open a malicious file — a classic file-parsing vulnerability. An attacker would need to deliver a malformed file to the target user through social engineering or other means, after which opening the file in Substance 3D Sampler triggers the memory corruption. No public proof-of-concept or detailed technical write-up has been identified at this time (Adobe Advisory, GitHub Advisory).
Successful exploitation allows an attacker to execute arbitrary code in the context of the current user, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker could read sensitive files, modify data, or crash the application. Since execution occurs within the user's context, the blast radius is limited to that user's privileges, though it could serve as a foothold for further lateral movement if the user has elevated permissions (Adobe Advisory, GitHub Advisory).
cmd.exe, powershell.exe, bash, curl, or other shells/utilities).Adobe has released a security update addressing this vulnerability; users should update Adobe Substance 3D Sampler to version 6.0.1 or later, as versions 6.0.0 and earlier are affected (Adobe Advisory). As a workaround, users should avoid opening Substance 3D Sampler files from untrusted or unknown sources. Organizations should educate users about the risks of opening files from unverified senders and consider restricting the application's network access as a defense-in-depth measure.
The vulnerability was noted in CISA's vulnerability bulletin (SB26-166) as part of Adobe's June 2026 patch cycle, and was covered by security aggregators including BeyondMachines and Fortress SRM in their June 2026 threat update summaries. No significant independent researcher commentary or notable social media discussion has been identified beyond automated CVE tracking posts.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."