Junglewise Threat Intelligence

CVE-2026-27279: Adobe Substance3D Stager out-of-bounds write

CVE-2026-27279 · Severity: high · CVSS 7.8 · Published 2026-03-10

Technologies: Adobe Substance 3d Stager, Apple macOS, Microsoft Windows, Adobe Substance3D Stager. Vendors: Adobe, Apple, Microsoft.

Executive brief

Adobe Substance3D Stager is a 3D asset preparation tool used by designers and developers to stage 3D content. Versions 3.1.7 and earlier contain an out-of-bounds write vulnerability that allows an attacker to execute arbitrary code when a victim opens a specially crafted malicious file. This could lead to unauthorized access, data theft, or system compromise.

Technical details

An out-of-bounds write vulnerability exists in Substance3D Stager versions 3.1.7 and earlier. The vulnerability is triggered when processing a malicious file, allowing an attacker to write data outside allocated memory boundaries. This leads to arbitrary code execution with the privileges of the current user. Exploitation requires user interaction—a victim must open a malicious file. The vulnerability affects Windows and/or macOS systems running the affected versions. A patch is expected to be available through Adobe's standard security update channels.

Affected products

  • Adobe Substance3D Stager 3.1.7 and earlier

Timeline

  • 2026-03-10: disclosed

References

Related threats