Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-75770
Adobe Substance 3D Painter vulnerability analysis and mitigation

Overview

CVE-2026-75770 is an out-of-bounds write vulnerability (CWE-787) in Adobe Substance3D - Painter that could result in arbitrary code execution in the context of the current user. All versions up to and including 12.1.2 are affected; version 12.1.3 is the first patched release. The vulnerability was published on August 25, 2026, with a patch made available the same day. It carries a CVSS v3.1 base score of 7.8 (High) (GitHub Advisory, Adobe Advisory).

Technical details

The vulnerability is classified as CWE-787 (Out-of-bounds Write), meaning the application writes data beyond the boundaries of an allocated buffer during file parsing. Exploitation requires a local attack vector — an attacker must craft a malicious file and convince a victim to open it within Substance3D - Painter, triggering the out-of-bounds write condition. No authentication or elevated privileges are required on the part of the attacker; the only precondition is user interaction (opening the malicious file). No public proof-of-concept or detailed technical write-up has been identified at this time (GitHub Advisory, Adobe Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running Substance3D - Painter, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker who achieves code execution could access or exfiltrate sensitive project files and credentials, modify or destroy data, and potentially use the compromised workstation as a pivot point for lateral movement within a network. The scope is limited to the affected host and user context, with no scope change beyond the vulnerable component (GitHub Advisory).

Exploitability

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept at this time. The NVD SSVC assessment confirms exploitation status as "none" and notes the vulnerability is not automatable, requiring user interaction to trigger. The EPSS score is approximately 0.148% (4th percentile), indicating a low near-term probability of exploitation. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog as of the latest available data (GitHub Advisory, Adobe Advisory).

Exploitation steps

  1. Craft malicious file: An attacker creates a specially crafted file (e.g., a project or asset file supported by Substance3D - Painter) that contains malformed data designed to trigger an out-of-bounds write when parsed by the application.
  2. Deliver the file: The attacker delivers the malicious file to a target user via phishing email, file-sharing platform, or social engineering, disguising it as a legitimate Substance3D Painter project or asset.
  3. Victim opens the file: The victim opens the malicious file in an unpatched version of Adobe Substance3D - Painter (≤ 12.1.2), triggering the vulnerable file-parsing code path.
  4. Out-of-bounds write triggered: The application writes data beyond the intended buffer boundary, corrupting adjacent memory structures in a controlled manner.
  5. Arbitrary code execution: The memory corruption is leveraged to redirect execution flow, achieving arbitrary code execution in the context of the current user — potentially enabling persistence, data theft, or further lateral movement (GitHub Advisory).

Indicators of compromise

  • Process: Unexpected child processes spawned by the Substance3D Painter process (e.g., cmd.exe, powershell.exe, bash, curl, or other shells/utilities not normally associated with the application).
  • File System: Newly created or modified files in user-writable directories (temp folders, AppData, home directory) shortly after opening a Substance3D Painter file; unexpected executables or scripts dropped alongside project files.
  • Network: Unusual outbound network connections originating from the Substance3D Painter process to external IP addresses, particularly shortly after a file is opened.
  • Logs: Application crash logs or Windows Event Log entries (Event ID 1000/1001) referencing Substance3D Painter around the time of file opening; memory access violation errors in application logs.

Mitigation and workarounds

Adobe has released version 12.1.3 of Substance3D - Painter, which addresses this vulnerability; users should update immediately via the Creative Cloud desktop application or Adobe's official download channels (Adobe Advisory). As a workaround prior to patching, users should avoid opening Substance3D Painter files received from untrusted or unexpected sources. Organizations should educate users about the risks of opening unsolicited files and consider restricting file sharing from external sources to reduce exposure.

Additional resources


SourceThis report was generated using AI

Related Adobe Substance 3D Painter vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-34674HIGH7.8
  • Adobe Substance 3D Painter logoAdobe Substance 3D Painter
  • cpe:2.3:a:adobe:substance_3d_painter
NoYesAug 27, 2026
CVE-2026-75770HIGH7.8
  • Adobe Substance 3D Painter logoAdobe Substance 3D Painter
  • cpe:2.3:a:adobe:substance_3d_painter
NoYesAug 25, 2026
CVE-2026-75769HIGH7.8
  • Adobe Substance 3D Painter logoAdobe Substance 3D Painter
  • cpe:2.3:a:adobe:substance_3d_painter
NoYesAug 25, 2026
CVE-2026-75768HIGH7.8
  • Adobe Substance 3D Painter logoAdobe Substance 3D Painter
  • cpe:2.3:a:adobe:substance_3d_painter
NoYesAug 25, 2026
CVE-2026-75767HIGH7.8
  • Adobe Substance 3D Painter logoAdobe Substance 3D Painter
  • cpe:2.3:a:adobe:substance_3d_painter
NoYesAug 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management