Junglewise Threat Intelligence

CVE-2026-27273: Adobe Substance3D Stager out-of-bounds write

CVE-2026-27273 · Severity: high · CVSS 7.8 · Published 2026-03-10

Technologies: Adobe Substance 3d Stager, Apple macOS, Microsoft Windows, Adobe Substance3D Stager. Vendors: Adobe, Apple, Microsoft.

Executive brief

Substance3D Stager is Adobe's 3D asset staging and configuration tool used by design and creative professionals. Versions 3.1.7 and earlier contain an out-of-bounds write vulnerability that allows an attacker to execute arbitrary code with the privileges of the user running the application. The vulnerability requires a victim to open a malicious file, making it exploitable through social engineering or phishing attacks.

Technical details

The vulnerability is a classic out-of-bounds write (CWE-787) in Substance3D Stager that permits memory corruption when processing specially crafted input files. The attack vector is local and requires user interaction—specifically, a victim must open a malicious file in the application. Successful exploitation allows an attacker to write arbitrary data to memory outside allocated buffers, leading to arbitrary code execution in the context of the current user. No authentication or privileged access is required prior to the attack; only the ability to get the user to open a malicious file. Adobe has issued patches for affected versions.

Affected products

  • Adobe Substance3D Stager 3.1.7 and earlier

Timeline

  • 2026-03-10: disclosed: Vulnerability published on NVD
  • 2026-03-10: advisory: Adobe security advisory APSB26-29 issued

References

Related threats