CVE-2026-75768CWE-426

CVE-2026-75768

High · published August 25, 2026

CVSS v3.1
7.8
EPSS
0%
Percentile
6.5
In the wild
Unconfirmed
What it is

Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

The record
Technical detail
CVSS v3.1
7.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00169 · 6.5th percentile
Weakness
CWE-426 · Untrusted Search Path
Published
2026-08-25T22:18Z
Affected products (1)
ProductVersionsFixed in
adobe/substance_3d_painter< 12.1.312.1.3
References (1)
EPSS history
Timeline
  • 27 AUG 06:45Z
    EPSS moved — → 0%
    epss
  • 25 AUG 17:58Z
    Substance3D - Painter | Untrusted Search Path (CWE-426)
    cvelistv5