CVE-2026-27273

7.8

Adobe · Substance3D Stager

Adobe Substance3D Stager contains an out-of-bounds write vulnerability that could allow an attacker to achieve arbitrary code execution through the opening of a malicious file.

Executive summary

Adobe Substance3D Stager versions 3.1.7 and earlier are vulnerable to an out-of-bounds write flaw that poses a critical risk of arbitrary code execution to end users.

Vulnerability

This vulnerability is an out-of-bounds write (CWE-787) triggered when a user opens a specially crafted file within the application. The attack requires user interaction and executes with the privileges of the currently logged-in user.

Business impact

Successful exploitation allows an attacker to execute arbitrary code in the context of the user, potentially leading to full system compromise or data exfiltration. Given the CVSS score of 7.8, this vulnerability is classified as High severity, representing a significant risk to organizational assets if users interact with untrusted 3D assets.

Remediation

Immediate Action: Update Adobe Substance3D Stager to version 3.1.8 or later to incorporate the vendor-supplied fix.

Proactive Monitoring: Monitor endpoint activity for unusual spawned processes or unexpected network connections originating from the Substance3D Stager application.

Compensating Controls: Implement strict file access policies and ensure users are trained to avoid opening 3D files from untrusted or unverified sources.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The vulnerability presents a clear path to code execution, necessitating prompt action. Organizations should prioritize updating all instances of Adobe Substance3D Stager to version 3.1.8 or higher to fully remediate the risk of arbitrary code execution.

More Adobe CVEs

Sources