Description
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.
Published: 2026-09-22
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Unauthorized write access via a security feature bypass
Action: Patch Now
AI Analysis

Impact

The vulnerability is an improper input validation flaw in Adobe's Content Credentials tool and SDK. It permits an attacker to craft inputs that bypass built‑in security checks, potentially leading to unauthorized write operations without any user interaction. The consequence is a loss of data integrity and possible further compromise if the attacker can modify critical configuration or code files.

Affected Systems

Adobe:Content Credentials Command-Line Tool and Adobe:Content Credentials Rust SDK are affected. No specific version range is provided, so all installations of these products are potentially vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, though the EPSS score is not available, making the exact exploit probability uncertain. The vulnerability is not listed in the CISA KEV catalog, suggesting no known public exploitation. The likely attack vector is local or service‑level input to the command‑line tool or SDK, requiring no privileged user interaction.

Generated by OpenCVE AI on September 22, 2026 at 20:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Adobe Content Credentials Command‑Line Tool to the latest patched release
  • Update the Adobe Content Credentials Rust SDK to a version that contains the input‑validation fix
  • Configure the tool’s directories with strict write permissions to limit unintended modifications
  • Monitor file‑system changes produced by the tool for unexpected write activity

Generated by OpenCVE AI on September 22, 2026 at 20:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Rust Sdk
Vendors & Products Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Rust Sdk

Tue, 22 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.
Title CAI Content Credentials | Improper Input Validation (CWE-20)
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Adobe Content Credentials Command-line Tool Content Credentials Rust Sdk
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-22T19:27:11.685Z

Reserved: 2026-08-10T15:34:28.300Z

Link: CVE-2026-19480

cve-icon Vulnrichment

Updated: 2026-09-22T19:27:01.031Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T19:16:43.053

Modified: 2026-09-22T20:17:02.427

Link: CVE-2026-19480

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T21:30:19Z

Weaknesses
  • CWE-20

    Improper Input Validation