Executive brief
Adobe Substance3D Stager is a 3D asset creation and staging tool used by design professionals. Versions 3.1.7 and earlier contain an out-of-bounds write flaw that allows an attacker to execute arbitrary code by tricking a user into opening a malicious file, potentially compromising the designer's system and gaining access to project files and credentials.
Technical details
The vulnerability is an out-of-bounds write flaw in Substance3D Stager versions 3.1.7 and earlier. The vulnerability requires user interaction—a victim must open a malicious file crafted to trigger the out-of-bounds write condition. Successful exploitation allows an attacker to execute arbitrary code in the security context of the logged-in user. This is a file-based attack vector that does not require network access or prior authentication. Adobe has released security advisories addressing this issue (APSB26-29).
Affected products
- Adobe Substance3D Stager 3.1.7 and earlier
Timeline
- 2026-03-10: disclosed