Executive brief
Substance3D Stager is Adobe's 3D asset staging and configuration tool used by design and creative professionals. Versions 3.1.7 and earlier contain an out-of-bounds write vulnerability that allows an attacker to execute arbitrary code with the privileges of the user running the application. The vulnerability requires a victim to open a malicious file, making it exploitable through social engineering or phishing attacks.
Technical details
The vulnerability is a classic out-of-bounds write (CWE-787) in Substance3D Stager that permits memory corruption when processing specially crafted input files. The attack vector is local and requires user interaction—specifically, a victim must open a malicious file in the application. Successful exploitation allows an attacker to write arbitrary data to memory outside allocated buffers, leading to arbitrary code execution in the context of the current user. No authentication or privileged access is required prior to the attack; only the ability to get the user to open a malicious file. Adobe has issued patches for affected versions.
Affected products
- Adobe Substance3D Stager 3.1.7 and earlier
Timeline
- 2026-03-10: disclosed: Vulnerability published on NVD
- 2026-03-10: advisory: Adobe security advisory APSB26-29 issued