Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.5

Substance3D - Painter versions 11.1.2 and earlier can crash from a malicious file

CVE-2026-27215
Summary

Older versions of Substance3D Painter can crash if you open a specially crafted file. This could disrupt your work and make it unavailable. Update to the latest version to fix the issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
adobe substance_3d_painter <= 11.1.3 –
Original title
Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerabi...
Original description
Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to its availability. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd CVSS3.1 5.5
Vulnerability type
CWE-476 NULL Pointer Dereference
Published: 10 Mar 2026 · Updated: 13 Mar 2026 · First seen: 10 Mar 2026