Executive brief
Substance3D Stager is a 3D design and prototyping tool used by creative professionals. A use-after-free vulnerability in versions 3.1.7 and earlier allows attackers to execute arbitrary code when a victim opens a malicious file, potentially compromising creative projects and system data.
Technical details
The vulnerability is a use-after-free defect in Substance3D Stager that permits arbitrary code execution within the context of the current user. The flaw requires user interaction—specifically, a victim must open a malicious file to trigger the vulnerability. This attack vector means the vulnerability is not remotely exploitable without social engineering. Affected versions are 3.1.7 and earlier. A patch is expected via Adobe's APSB26-29 bulletin (currently access-restricted), indicating a fix is available or forthcoming.
Affected products
- Adobe Substance3D Stager 3.1.7 and earlier
Timeline
- 2026-03-27: disclosed