Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-75767
Adobe Substance 3D Painter vulnerability analysis and mitigation

Overview

CVE-2026-75767 is a Heap-based Buffer Overflow vulnerability in Adobe Substance3D - Painter that could result in arbitrary code execution in the context of the current user. All versions up to and including 12.1.2 are affected; version 12.1.3 is the first patched release. The vulnerability was published on August 25, 2026, with an advisory issued by Adobe. It carries a CVSS v3.1 base score of 7.8 (High) (GitHub Advisory, Adobe Advisory).

Technical details

The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow), where memory allocated on the heap can be overwritten beyond its intended bounds during the processing of a maliciously crafted file. An attacker exploits this by crafting a specially formed file that, when opened by a victim in Substance3D - Painter, triggers an out-of-bounds write to heap memory. The attack vector is local (the file must be opened on the victim's machine), requires no privileges, but does require user interaction. No public proof-of-concept or detailed technical write-up has been identified at this time (GitHub Advisory, Adobe Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary code in the security context of the current user, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker who achieves code execution could access sensitive files, install malware, or pivot to other systems accessible by the compromised user account. The scope is limited to the local system (unchanged scope), but the full triad of CIA impacts is rated High (GitHub Advisory).

Exploitability

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept at this time. The NVD SSVC assessment confirms exploitation status as "none" and the attack is not automatable, as it requires a victim to manually open a malicious file. The EPSS score is approximately 0.186%, placing it in the 8th percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Adobe Advisory).

Exploitation steps

  1. Craft a malicious file: Create a specially crafted file in a format supported by Substance3D - Painter (e.g., a project or texture file) that contains malformed data designed to trigger a heap buffer overflow during parsing.
  2. Deliver the file to the victim: Use social engineering, phishing, or file-sharing platforms to deliver the malicious file to a target user who has Substance3D - Painter version 12.1.2 or earlier installed.
  3. Induce the victim to open the file: Trick the victim into opening the malicious file with Substance3D - Painter, for example by disguising it as a legitimate asset or project file.
  4. Trigger the heap overflow: When the application parses the malformed file, the heap-based buffer overflow is triggered, overwriting adjacent heap memory with attacker-controlled data.
  5. Achieve arbitrary code execution: By controlling the overwritten memory (e.g., function pointers or heap metadata), the attacker redirects execution flow to a shellcode or ROP chain, executing arbitrary code in the context of the current user (GitHub Advisory).

Indicators of compromise

  • Process: Unexpected child processes spawned by the Substance3D - Painter process (e.g., cmd.exe, powershell.exe, bash, curl, or network utilities).
  • File System: Presence of unexpected files (scripts, executables, or payloads) written to user-accessible directories shortly after opening a Substance3D - Painter file.
  • Network: Unusual outbound network connections originating from the Substance3D - Painter process to unknown external IP addresses or domains.
  • Logs: Application crash logs or Windows Event Logs indicating abnormal termination or access violations in the Substance3D - Painter process around the time a file was opened.

Mitigation and workarounds

Adobe has released Substance3D - Painter version 12.1.3 to address this vulnerability; users should update immediately via the Adobe Creative Cloud application or Adobe's official download channels (Adobe Advisory). As a workaround prior to patching, users should avoid opening Substance3D - Painter files received from untrusted or unknown sources. Organizations may also consider implementing file sandboxing or restricting the application's network access to limit the impact of potential exploitation.

Additional resources


SourceThis report was generated using AI

Related Adobe Substance 3D Painter vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-34674HIGH7.8
  • Adobe Substance 3D Painter logoAdobe Substance 3D Painter
  • cpe:2.3:a:adobe:substance_3d_painter
NoYesAug 27, 2026
CVE-2026-75770HIGH7.8
  • Adobe Substance 3D Painter logoAdobe Substance 3D Painter
  • cpe:2.3:a:adobe:substance_3d_painter
NoYesAug 25, 2026
CVE-2026-75769HIGH7.8
  • Adobe Substance 3D Painter logoAdobe Substance 3D Painter
  • cpe:2.3:a:adobe:substance_3d_painter
NoYesAug 25, 2026
CVE-2026-75768HIGH7.8
  • Adobe Substance 3D Painter logoAdobe Substance 3D Painter
  • cpe:2.3:a:adobe:substance_3d_painter
NoYesAug 25, 2026
CVE-2026-75767HIGH7.8
  • Adobe Substance 3D Painter logoAdobe Substance 3D Painter
  • cpe:2.3:a:adobe:substance_3d_painter
NoYesAug 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management