Junglewise Threat Intelligence

CVE-2026-27219: Adobe Substance3D Painter out-of-bounds read in memory parsing

CVE-2026-27219 · Severity: medium · CVSS 5.5 · Published 2026-03-10

Technologies: Adobe Substance3D Painter, Adobe Substance 3d Painter. Vendors: Adobe.

Executive brief

Adobe Substance3D Painter is a professional 3D design and texturing application used by digital artists and game developers. Versions 11.1.2 and earlier contain an out-of-bounds read vulnerability that allows attackers to access sensitive data stored in application memory by tricking users into opening a malicious file. This could expose confidential project data or credentials.

Technical details

The vulnerability is an out-of-bounds read flaw in Substance3D Painter's file parsing logic that occurs when processing specially crafted input files. The defect allows an attacker to read memory regions beyond the intended bounds of a buffer, potentially exposing sensitive information such as encryption keys, user data, or other confidential content stored in the application's memory space. Exploitation requires user interaction: a victim must be tricked into opening a malicious file. The vulnerability affects versions 11.1.2 and earlier; patch status and availability of fixes should be verified through Adobe's official security bulletin.

Affected products

  • Adobe Substance3D Painter 11.1.2 and earlier

Timeline

  • 2026-03-10: disclosed: CVE published on NVD
  • 2026-03-10: advisory: Adobe security bulletin APSB26-25 issued

References

Related threats