CVE-2026-75768
Received Received - Intake

Adobe Substance3D Painter Untrusted Search Path Vulnerability

Vulnerability report for CVE-2026-75768, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-25

Assigner: Adobe Systems Incorporated

Description

Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-25
Generated
2026-08-25
AI Q&A
2026-08-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
adobe painter *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-426 The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Substance3D Painter has an Untrusted Search Path vulnerability that allows arbitrary code execution. This means an attacker could run malicious code on a victim's system if they open a specially crafted file. The vulnerability requires user interaction to exploit.

Detection Guidance

Detection involves monitoring for suspicious file execution or unusual process activity. Check for files opened from untrusted sources or unexpected child processes spawned by Substance3D Painter. Review system logs for unauthorized code execution attempts.

Impact Analysis

If exploited, this vulnerability could allow an attacker to take control of your computer, install malware, or steal data. Since it requires opening a malicious file, users should avoid downloading files from untrusted sources.

Compliance Impact

This vulnerability could lead to arbitrary code execution, potentially compromising user data confidentiality and integrity. Such breaches may violate GDPR's data protection requirements and HIPAA's safeguards for protected health information, depending on the data processed by the affected software.

Mitigation Strategies

Update Substance3D Painter to the latest version. Avoid opening files from untrusted sources. Restrict user permissions to minimize impact if exploited. Monitor for unusual activity in the application.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75768. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart