CVE-2026-48306
published 2026-06-09CVE-2026-48306: Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the…
PriorityP344high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.14%
3.9th percentile
Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | substance3d_sampler | <= 6.0.0 | — |
| adobe | substance_3d_sampler | < 6.0.1 | 6.0.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user.
ghsa_unreviewed·2026-06-09
CVE-2026-48306 [HIGH] CWE-787 Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user.
Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
VulDB
Adobe Substance3D Sampler up to 6.0.0 File out-of-bounds write (apsb26-60)
vuldb·2026-06-09·CVSS 7.8
CVE-2026-48306 [HIGH] Adobe Substance3D Sampler up to 6.0.0 File out-of-bounds write (apsb26-60)
A vulnerability identified as critical has been detected in Adobe Substance3D Sampler up to 6.0.0. Affected is an unknown function of the component File Handler. This manipulation causes out-of-bounds write.
This vulnerability appears as CVE-2026-48306. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-09
Published