
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-75770 is an out-of-bounds write vulnerability (CWE-787) in Adobe Substance3D - Painter that could result in arbitrary code execution in the context of the current user. All versions up to and including 12.1.2 are affected; version 12.1.3 is the first patched release. The vulnerability was published on August 25, 2026, with a patch made available the same day. It carries a CVSS v3.1 base score of 7.8 (High) (GitHub Advisory, Adobe Advisory).
The vulnerability is classified as CWE-787 (Out-of-bounds Write), meaning the application writes data beyond the boundaries of an allocated buffer during file parsing. Exploitation requires a local attack vector — an attacker must craft a malicious file and convince a victim to open it within Substance3D - Painter, triggering the out-of-bounds write condition. No authentication or elevated privileges are required on the part of the attacker; the only precondition is user interaction (opening the malicious file). No public proof-of-concept or detailed technical write-up has been identified at this time (GitHub Advisory, Adobe Advisory).
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running Substance3D - Painter, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker who achieves code execution could access or exfiltrate sensitive project files and credentials, modify or destroy data, and potentially use the compromised workstation as a pivot point for lateral movement within a network. The scope is limited to the affected host and user context, with no scope change beyond the vulnerable component (GitHub Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept at this time. The NVD SSVC assessment confirms exploitation status as "none" and notes the vulnerability is not automatable, requiring user interaction to trigger. The EPSS score is approximately 0.148% (4th percentile), indicating a low near-term probability of exploitation. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog as of the latest available data (GitHub Advisory, Adobe Advisory).
cmd.exe, powershell.exe, bash, curl, or other shells/utilities not normally associated with the application).Adobe has released version 12.1.3 of Substance3D - Painter, which addresses this vulnerability; users should update immediately via the Creative Cloud desktop application or Adobe's official download channels (Adobe Advisory). As a workaround prior to patching, users should avoid opening Substance3D Painter files received from untrusted or unexpected sources. Organizations should educate users about the risks of opening unsolicited files and consider restricting file sharing from external sources to reduce exposure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."