CVE-2026-48429
Received Received - Intake

NULL Pointer Dereference in Adobe Substance3D Designer

Vulnerability report for CVE-2026-48429, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-25

Assigner: Adobe Systems Incorporated

Description

Substance3D - Designer is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-25
Generated
2026-08-25
AI Q&A
2026-08-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
adobe substance3d_designer *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a NULL Pointer Dereference vulnerability in Adobe Substance3D Designer. It allows an attacker to crash the application by exploiting a flaw that causes the program to dereference a NULL pointer, leading to a denial-of-service condition. The attacker must trick a user into opening a specially crafted malicious file to trigger this issue.

Detection Guidance

Detection involves monitoring for crashes when opening files in Substance3D Designer. Check application logs for NULL pointer dereference errors after opening suspicious files. No specific commands are provided in the context.

Impact Analysis

If you use Adobe Substance3D Designer, an attacker could exploit this vulnerability to crash the application. This would disrupt your workflow and could lead to loss of unsaved work. Since exploitation requires user interaction, you are only at risk if you open a malicious file.

Compliance Impact

This vulnerability causes a denial-of-service via application crash, which may disrupt services handling sensitive data. GDPR requires ensuring availability of personal data processing systems, so prolonged outages could impact compliance. HIPAA mandates availability of ePHI systems, making such disruptions a potential compliance risk if not mitigated promptly.

Mitigation Strategies

Update Substance3D Designer to the latest version. Avoid opening files from untrusted sources. Implement application allowlisting to restrict execution of unapproved files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-48429. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart