CVE-2026-75768
Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.8
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS probability
- 0.17%
- CWE
- CWE-426
- Published
- 2026-08-25
- Last modified
- 2026-08-28
Affected products
- Adobe Adobe Substance 3D Painter
- Adobe Adobe Substance 3D Painter
- Adobe Substance3D - Painter
- Adobe Substance3D - Painter
Weakness type
Related vulnerabilities
- CVE-2026-0307 — GlobalProtect App: Local Privilege Escalation Vulnerabilities
- CVE-2026-80159 — Acrobat Reader | Untrusted Search Path (CWE-426)
- CVE-2026-81192 — OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS
- CVE-2026-78574 — Improper Assembly Resolution in Okta Hyperdrive Integration Plugin Registry Handling
- CVE-2026-69785 — Windows Smart Card Elevation of Privilege Vulnerability
- CVE-2026-69328 — Windows Storage Elevation of Privilege Vulnerability
- CVE-2026-84226 — OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local...
- CVE-2026-82862 — Hulumi before v1.3.2 Helper Script Shadowing via Workspace Files