Description
CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Published: 2026-05-12
Score: 6.2 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Improper Input Validation flaw, classified as CWE‑20, in Adobe CAI Content Credentials that allows an attacker to supply malformed input that causes the application to crash. The crash results in a denial‑of‑service for any service using the credentials component. No evidence is provided that the flaw leads to code execution, data disclosure, or privilege escalation, so the primary impact is loss of availability.

Affected Systems

Adobe CAI Content Credentials versions 0.78.2, 0.7.0, and all earlier releases are affected. Any system or application that incorporates these versions of the credentials component is vulnerable.

Risk and Exploitability

The CVSS score of 6.2 indicates moderate severity. Because the EPSS score is not available and the flaw is not listed in CISA’s KEV catalog, the likelihood of exploitation remains uncertain, although the description states that no user interaction is required. This implies that an attacker could trigger the crash remotely, potentially using crafted network input or a web request. Until a patch is applied, the risk is moderate but could become severe if the flaw is actively abused.

Generated by OpenCVE AI on May 12, 2026 at 22:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Adobe CAI Content Credentials to a later version that removes the Improper Input Validation flaw.
  • Restart the credentials service after updating to clear any retained crashed state.
  • Implement process monitoring so that an automated restart occurs if the service unexpectedly exits, thereby reducing downtime while a patch is deployed.

Generated by OpenCVE AI on May 12, 2026 at 22:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 12 May 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 May 2026 20:15:00 +0000

Type Values Removed Values Added
Description CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Title CAI Content Credentials | Improper Input Validation (CWE-20)
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-05-12T20:24:37.896Z

Reserved: 2026-03-30T17:30:36.496Z

Link: CVE-2026-34679

cve-icon Vulnrichment

Updated: 2026-05-12T20:24:32.333Z

cve-icon NVD

Status : Received

Published: 2026-05-12T20:16:38.257

Modified: 2026-05-12T20:16:38.257

Link: CVE-2026-34679

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-12T22:15:25Z

Weaknesses