Description
CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Published: 2026-08-11
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a server‑side request forgery (SSRF) that can allow an attacker to direct the affected server to make arbitrary outgoing requests. The greatest risk is privilege escalation, occurring when the exploited server has elevated rights. The fault resides in the handling of external URLs, as identified by CWE‑918. The description indicates that the vulnerability is limited to scenarios where a user visits a crafted URL or interacts with a compromised web page, so exploitation requires user interaction.

Affected Systems

Adobe Content Credentials Command‑Line Tool, Adobe Content Credentials JavaScript SDK, and Adobe Content Credentials Rust SDK are affected. No specific version numbers are supplied in the available data.

Risk and Exploitability

The CVSS score is 4.7, indicating moderate severity; however, the EPSS probability is below 1 % and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote, mediated by a malicious URL or compromised site that a user must access. Because the vulnerability works only after user interaction, the chance of a large‑scale exploitation is low but not impossible if a target is tricked into visiting a malicious link. If successful, the attacker may bypass controls and gain additional privileges on the affected system.

Generated by OpenCVE AI on August 12, 2026 at 21:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available vendor patches or updates for Adobe Content Credentials Command‑Line Tool, JavaScript SDK, and Rust SDK.
  • Configure network controls to restrict outbound requests from the Content Credentials processes to only trusted destinations.
  • Implement web filtering or security gateways that block or quarantine user visits to malicious URLs that could trigger SSRF.

Generated by OpenCVE AI on August 12, 2026 at 21:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe c2pa
Adobe c2pa-web
Adobe c2patool
CPEs cpe:2.3:a:adobe:c2pa-web:*:*:*:*:*:node.js:*:*
cpe:2.3:a:adobe:c2pa:*:*:*:*:*:rust:*:*
cpe:2.3:a:adobe:c2patool:*:*:*:*:*:*:*:*
Vendors & Products Adobe c2pa
Adobe c2pa-web
Adobe c2patool

Thu, 13 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk
Vendors & Products Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk

Wed, 12 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Title CAI Content Credentials | Server-Side Request Forgery (SSRF) (CWE-918)
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N'}


Subscriptions

Adobe C2pa C2pa-web C2patool Content Credentials Command-line Tool Content Credentials Js Sdk Content Credentials Rust Sdk
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:33:56.587Z

Reserved: 2026-05-20T15:50:31.360Z

Link: CVE-2026-47922

cve-icon Vulnrichment

Updated: 2026-08-12T15:02:24.330Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:17:59.380

Modified: 2026-08-28T00:17:30.560

Link: CVE-2026-47922

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T02:45:03Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)