
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27273 is an out-of-bounds write vulnerability (CWE-787) in Adobe Substance 3D Stager that can result in arbitrary code execution in the context of the current user. It affects Substance 3D Stager versions 3.1.7 and earlier (all versions prior to 3.1.8). Adobe disclosed and patched the vulnerability on March 10, 2026, as part of its March 2026 security update cycle. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Adobe Advisory).
The vulnerability is classified as CWE-787 (Out-of-bounds Write), meaning the application writes data beyond the bounds of an allocated memory buffer during file parsing. Exploitation requires a victim to open a specially crafted malicious file, making this a local, user-interaction-required attack vector. No authentication or elevated privileges are required on the part of the attacker — the attacker only needs to deliver a malicious file and convince the target to open it with Substance 3D Stager. No public technical write-ups or proof-of-concept code have been identified at this time (Adobe Advisory).
Successful exploitation allows an unauthenticated attacker to execute arbitrary code in the security context of the current user, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker could read sensitive files, modify or destroy data, or cause the application to crash. Since code execution occurs under the victim's user account, the blast radius is limited to that user's privileges, though it could serve as a foothold for further lateral movement in enterprise environments (Adobe Advisory).
.sbs or supported scene file) that triggers an out-of-bounds write during parsing by embedding malformed data in a field processed by the vulnerable code path..sbs, .sbsar, or scene files) received via email or downloaded from untrusted sources; new or modified files in user profile directories shortly after opening a Stager file.cmd.exe, powershell.exe, bash, curl, or other scripting/network utilities).Adobe has released Substance 3D Stager version 3.1.8, which addresses this vulnerability. Users should update to version 3.1.8 or later immediately via the Creative Cloud desktop application or Adobe's official download channels. As a workaround prior to patching, users should avoid opening Substance 3D Stager files received from untrusted or unknown sources. Organizations should also consider user awareness training to reduce the risk of social engineering attacks leveraging malicious files (Adobe Advisory).
The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in Adobe products, including this one, could allow for arbitrary code execution, recommending prompt patching (CIS Advisory). The vulnerability received routine coverage from security aggregators and threat intelligence platforms, with no notable researcher commentary or significant social media discussion beyond standard patch-Tuesday reporting.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."