
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27215 is a NULL Pointer Dereference vulnerability in Adobe Substance 3D Painter that can cause application-level denial of service. It affects Substance 3D Painter versions 11.1.2 and earlier, with version 11.1.3 being the first patched release. The vulnerability was disclosed on March 10, 2026, as part of Adobe's March 2026 security update cycle. It carries a CVSS v3.1 base score of 5.5 (Medium) (Adobe Advisory).
The vulnerability is classified as CWE-476 (NULL Pointer Dereference), occurring within the file parsing logic of Adobe Substance 3D Painter. An attacker can craft a malicious file that, when opened by a victim, triggers a null pointer dereference and causes the application to crash. Exploitation requires local access and user interaction — specifically, a victim must open the malicious file — making the attack vector local (AV:L) with no privileges required. No technical write-ups or public proof-of-concept code have been identified at this time (Adobe Advisory).
Successful exploitation results in an application-level denial of service, crashing the Substance 3D Painter process and disrupting availability until the application is restarted. There is no impact on confidentiality or integrity, as the vulnerability does not enable code execution, data access, or privilege escalation. The scope is limited to the affected application on the local system, with no potential for lateral movement or data exfiltration (Adobe Advisory).
Adobe Substance 3D Painter.exe) with null pointer or access violation exceptions..spp) received from external or unknown sources.Adobe Substance 3D Painter.exe process, particularly shortly after opening a file from an untrusted source.Adobe has released Substance 3D Painter version 11.1.3 to address this vulnerability; users should upgrade immediately. No configuration-based workaround is available, so patching is the only definitive remediation. As an interim measure, users should be advised not to open Substance 3D Painter files received from untrusted or unexpected sources (Adobe Advisory).
The CIS (Center for Internet Security) issued an advisory noting multiple vulnerabilities in Adobe products patched in March 2026, including this issue, flagging potential for disruption in affected environments (CIS Advisory). Beyond Machines and other security news aggregators covered Adobe's March 2026 patch release broadly. No notable individual researcher commentary or significant social media discussion specific to CVE-2026-27215 has been observed, consistent with its medium severity and limited exploitation potential.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."