Junglewise Threat Intelligence

CVE-2026-27274: Adobe Substance3D Stager out-of-bounds write

CVE-2026-27274 · Severity: high · CVSS 7.8 · Published 2026-03-10

Technologies: Adobe Substance 3d Stager, Apple macOS, Microsoft Windows, Adobe Substance3D Stager. Vendors: Adobe, Apple, Microsoft.

Executive brief

Adobe Substance3D Stager is a 3D asset creation and staging tool used by design professionals. Versions 3.1.7 and earlier contain an out-of-bounds write flaw that allows an attacker to execute arbitrary code by tricking a user into opening a malicious file, potentially compromising the designer's system and gaining access to project files and credentials.

Technical details

The vulnerability is an out-of-bounds write flaw in Substance3D Stager versions 3.1.7 and earlier. The vulnerability requires user interaction—a victim must open a malicious file crafted to trigger the out-of-bounds write condition. Successful exploitation allows an attacker to execute arbitrary code in the security context of the logged-in user. This is a file-based attack vector that does not require network access or prior authentication. Adobe has released security advisories addressing this issue (APSB26-29).

Affected products

  • Adobe Substance3D Stager 3.1.7 and earlier

Timeline

  • 2026-03-10: disclosed

References

Related threats