
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-75767 is a Heap-based Buffer Overflow vulnerability in Adobe Substance3D - Painter that could result in arbitrary code execution in the context of the current user. All versions up to and including 12.1.2 are affected; version 12.1.3 is the first patched release. The vulnerability was published on August 25, 2026, with an advisory issued by Adobe. It carries a CVSS v3.1 base score of 7.8 (High) (GitHub Advisory, Adobe Advisory).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow), where memory allocated on the heap can be overwritten beyond its intended bounds during the processing of a maliciously crafted file. An attacker exploits this by crafting a specially formed file that, when opened by a victim in Substance3D - Painter, triggers an out-of-bounds write to heap memory. The attack vector is local (the file must be opened on the victim's machine), requires no privileges, but does require user interaction. No public proof-of-concept or detailed technical write-up has been identified at this time (GitHub Advisory, Adobe Advisory).
Successful exploitation allows an attacker to execute arbitrary code in the security context of the current user, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker who achieves code execution could access sensitive files, install malware, or pivot to other systems accessible by the compromised user account. The scope is limited to the local system (unchanged scope), but the full triad of CIA impacts is rated High (GitHub Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept at this time. The NVD SSVC assessment confirms exploitation status as "none" and the attack is not automatable, as it requires a victim to manually open a malicious file. The EPSS score is approximately 0.186%, placing it in the 8th percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Adobe Advisory).
cmd.exe, powershell.exe, bash, curl, or network utilities).Adobe has released Substance3D - Painter version 12.1.3 to address this vulnerability; users should update immediately via the Adobe Creative Cloud application or Adobe's official download channels (Adobe Advisory). As a workaround prior to patching, users should avoid opening Substance3D - Painter files received from untrusted or unknown sources. Organizations may also consider implementing file sandboxing or restricting the application's network access to limit the impact of potential exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."