CVE-2026-27273
7.8Adobe · Substance3D Stager
Adobe Substance3D Stager contains an out-of-bounds write vulnerability that could allow an attacker to achieve arbitrary code execution through the opening of a malicious file.
Executive summary
Adobe Substance3D Stager versions 3.1.7 and earlier are vulnerable to an out-of-bounds write flaw that poses a critical risk of arbitrary code execution to end users.
Vulnerability
This vulnerability is an out-of-bounds write (CWE-787) triggered when a user opens a specially crafted file within the application. The attack requires user interaction and executes with the privileges of the currently logged-in user.
Business impact
Successful exploitation allows an attacker to execute arbitrary code in the context of the user, potentially leading to full system compromise or data exfiltration. Given the CVSS score of 7.8, this vulnerability is classified as High severity, representing a significant risk to organizational assets if users interact with untrusted 3D assets.
Remediation
Immediate Action: Update Adobe Substance3D Stager to version 3.1.8 or later to incorporate the vendor-supplied fix.
Proactive Monitoring: Monitor endpoint activity for unusual spawned processes or unexpected network connections originating from the Substance3D Stager application.
Compensating Controls: Implement strict file access policies and ensure users are trained to avoid opening 3D files from untrusted or unverified sources.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The vulnerability presents a clear path to code execution, necessitating prompt action. Organizations should prioritize updating all instances of Adobe Substance3D Stager to version 3.1.8 or higher to fully remediate the risk of arbitrary code execution.