NULL Pointer Dereference Vulnerability in Adobe Substance3D - Painter
CVE-2026-27217

5.5MEDIUM

Key Information:

Vendor

Adobe

Vendor
CVE Published:
10 March 2026

What is CVE-2026-27217?

Adobe Substance3D - Painter, specifically versions 11.1.2 and earlier, includes a vulnerability that manifests as a NULL Pointer Dereference, which may result in a denial-of-service condition. This weakness can allow an attacker to crash the application, disrupting its normal functionality. Exploitation requires user interaction, as a victim must open a specially crafted malicious file to trigger the issue. Users are advised to update their software to newer versions to mitigate risks associated with this vulnerability.

Affected Version(s)

Substance3D - Painter 0 <= 11.1.2

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.