Junglewise Threat Intelligence

CVE-2026-27215: Adobe Substance3D Painter NULL pointer dereference

CVE-2026-27215 · Severity: medium · CVSS 5.5 · Published 2026-03-10

Technologies: Adobe Substance3D Painter, Adobe Substance 3d Painter. Vendors: Adobe.

Executive brief

Adobe Substance3D Painter is a 3D design tool used by artists and designers for texture creation and painting. Versions 11.1.2 and earlier contain a flaw that allows attackers to crash the application by sending a specially crafted file, disrupting work and causing denial of service to end users.

Technical details

Substance3D Painter versions 11.1.2 and earlier are vulnerable to a NULL pointer dereference, a memory access error that occurs when the application attempts to use a pointer that has not been initialized or has been set to NULL. The vulnerability is triggered when a user opens a malicious file, making user interaction a prerequisite for exploitation. Successful exploitation crashes the application, resulting in denial of service but not code execution or data theft. Adobe has released patches to address this issue in newer versions.

Affected products

  • Adobe Substance3D Painter 11.1.2 and earlier

Timeline

  • 2026-03-10: disclosed

References

Related threats