CVE-2026-27274: Substance3D - Stager | Out-of-bounds Write (CWE-787)
Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27274?
CVE-2026-27274 is considered a high severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2026-27274?
To fix CVE-2026-27274, update to a version of Substance3D Stager that is later than 3.1.7.
What types of systems are affected by CVE-2026-27274?
CVE-2026-27274 affects Substance3D Stager versions 3.1.7 and earlier on any system where this software is installed.
What is the impact of exploiting CVE-2026-27274?
Exploitation of CVE-2026-27274 can lead to arbitrary code execution in the context of the current user, posing significant security risks.
Is user interaction required to exploit CVE-2026-27274?
Yes, exploitation of CVE-2026-27274 requires user interaction.