Description
CAI Content Credentials is affected by an Insufficiently Protected Credentials vulnerability that could result in disclosure of sensitive information. An attacker could leverage this vulnerability to gain unauthorized read access. Exploitation of this issue does not require user interaction.
Published: 2026-07-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Insufficiently Protected Credentials flaw that allows an attacker to read protected data transmitted or stored by the Adobe Content Credentials components. By exploiting unencrypted or otherwise insecure credentials, an unauthorized party can obtain sensitive information without any user interaction. The flaw is identified as CWE‑522.

Affected Systems

Adobe Content Credentials Command‑Line Tool, Adobe Content Credentials JS SDK, and Adobe Content Credentials Rust SDK are affected. No specific version numbers are listed, so all current installations of these tools remain vulnerable until a vendor fix is released.

Risk and Exploitability

The CVSS score of 7.5 classifies the issue as high severity, and the EPSS score of less than 1% indicates that exploitation is unlikely but still possible. The vulnerability is not yet in CISA’s KEV catalog. Exploitation does not require user interaction, meaning an attacker who can reach the affected components could immediately extract confidential credentials or other protected data.

Generated by OpenCVE AI on July 31, 2026 at 04:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Adobe Content Credentials patch that addresses the credential protection flaw.
  • Configure the tools to encrypt or otherwise secure any stored or transmitted credentials; eliminate plaintext storage where possible.
  • Restrict access to the command‑line tool and SDKs using least‑privilege principles, and enforce secure communication channels for any credential transmission.

Generated by OpenCVE AI on July 31, 2026 at 04:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk
Vendors & Products Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk

Wed, 15 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description CAI Content Credentials is affected by an Insufficiently Protected Credentials vulnerability that could result in disclosure of sensitive information. An attacker could leverage this vulnerability to gain unauthorized read access. Exploitation of this issue does not require user interaction.
Title CAI Content Credentials | Insufficiently Protected Credentials (CWE-522)
Weaknesses CWE-522
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Adobe Content Credentials Command-line Tool Content Credentials Js Sdk Content Credentials Rust Sdk
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-14T23:39:11.628Z

Reserved: 2026-05-21T15:28:38.135Z

Link: CVE-2026-48295

cve-icon Vulnrichment

Updated: 2026-07-14T23:33:51.730Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:36:32Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials