Junglewise Threat Intelligence

CVE-2026-27214: Adobe Substance3D Painter NULL pointer dereference

CVE-2026-27214 · Severity: medium · CVSS 5.5 · Published 2026-03-10

Technologies: Adobe Substance3D Painter, Adobe Substance 3d Painter. Vendors: Adobe.

Executive brief

Substance3D Painter, a professional 3D painting and texturing application, contains a vulnerability that allows attackers to crash the application by tricking users into opening a malicious file. This causes service disruption and prevents artists from working until the application is restarted.

Technical details

The vulnerability is a NULL pointer dereference in Substance3D Painter versions 11.1.2 and earlier. The flaw occurs when the application processes a malicious or specially crafted file, leading to a crash. Exploitation requires user interaction—a victim must open the malicious file—making it a local attack vector. An attacker cannot remotely trigger this vulnerability or gain code execution; the impact is limited to denial-of-service (application crash). Patches for versions after 11.1.2 are available.

Affected products

  • Adobe Substance3D Painter 11.1.2 and earlier

Timeline

  • 2026-03-10: disclosed

References

Related threats