Description
CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Published: 2026-07-14
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CAI Content Credentials contains a Server‑Side Request Forgery vulnerability that allows an attacker to direct the server to fetch arbitrary URLs. This can result in injection of malicious scripts into web pages, providing the attacker with elevated access or control over the victim’s account or session, and the potential for arbitrary code execution in the context of the victim user. The exploitation requires user interaction, such as visiting a maliciously crafted URL or interacting with a compromised web page, and changes the scope of the vulnerability.

Affected Systems

Adobe Content Credentials Command‑Line Tool, Adobe Content Credentials JavaScript SDK, and Adobe Content Credentials Rust SDK are all affected. Version information is not specified, so any current version of these tools could be vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity, while the EPSS score of <1% suggests a low but non‑zero likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, involving crafted URLs or malicious web pages, and requires a victim to interact with the malicious content.

Generated by OpenCVE AI on August 1, 2026 at 09:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch that addresses the SSRF issue for all affected Adobe Content Credentials tools.
  • If a patch is not yet available, restrict outbound network requests from the application to only trusted endpoints using firewall or proxy rules to prevent unwanted server–side requests.
  • Implement input validation or URL filtering to reject suspicious or disallowed URLs before they reach the application or browser.

Generated by OpenCVE AI on August 1, 2026 at 09:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk
Vendors & Products Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk

Wed, 15 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Title CAI Content Credentials | Server-Side Request Forgery (SSRF) (CWE-918)
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

Adobe Content Credentials Command-line Tool Content Credentials Js Sdk Content Credentials Rust Sdk
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-14T23:39:11.773Z

Reserved: 2026-05-21T15:28:38.134Z

Link: CVE-2026-48290

cve-icon Vulnrichment

Updated: 2026-07-14T23:33:53.206Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:36:34Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)