Impact
CAI Content Credentials is vulnerable to an untrusted search path flaw that permits an attacker to execute arbitrary code in the context of the user who runs the affected tool or SDK. The flaw is rooted in the way the application resolves executables, allowing a malicious binary to be found before the intended trusted binary. When triggered, the attacker can gain full control of the affected process, potentially impacting all data and services accessed by that user.
Affected Systems
The vulnerability affects Adobe Content Credentials Command‑Line Tool, Adobe Content Credentials JavaScript SDK, and Adobe Content Credentials Rust SDK. No specific version information was supplied, so all currently released versions should be treated as vulnerable until a vendor‑issued patch is applied.
Risk and Exploitability
The CVSS score of 7.4 marks this as a high‑severity issue, yet the EPSS score indicates a very low probability of exploitation in the wild. The vulnerability requires user interaction – a victim must inadvertently visit a malicious URL or engage with a compromised web page – to trigger the exploit, limiting spontaneous attacks. Because the flaw changes scope, the attacker may affect additional processes or services accessed by that user. Although the vulnerability is not listed in the CISA KEV catalog, security teams should consider it a potential threat vector and act proactively.
OpenCVE Enrichment