Junglewise Threat Intelligence

CVE-2026-27218: Adobe Substance3D Painter NULL pointer dereference

CVE-2026-27218 · Severity: medium · CVSS 5.5 · Published 2026-03-10

Technologies: Adobe Substance3D Painter, Adobe Substance 3d Painter. Vendors: Adobe.

Executive brief

Adobe Substance3D Painter is a 3D digital art application used by designers and artists for texture painting and asset creation. A NULL pointer dereference vulnerability in Painter versions 11.1.2 and earlier can be triggered when opening a malicious file, causing the application to crash and disrupting creative work and project timelines.

Technical details

The vulnerability is a NULL pointer dereference in Substance3D Painter versions 11.1.2 and earlier. The flaw requires user interaction—specifically opening a specially crafted malicious file—to trigger the crash. An attacker can exploit this to cause a denial-of-service condition by crashing the application. The attack vector is local (file-based) and impacts availability of the application. Patches are expected to be available in later versions after 11.1.2.

Affected products

  • Adobe Substance3D Painter 11.1.2 and earlier

Timeline

  • 2026-03-10: disclosed

References

Related threats