Impact
The vulnerability is an Insufficiently Protected Credentials flaw that allows an attacker to read protected data transmitted or stored by the Adobe Content Credentials components. By exploiting unencrypted or otherwise insecure credentials, an unauthorized party can obtain sensitive information without any user interaction. The flaw is identified as CWE‑522.
Affected Systems
Adobe Content Credentials Command‑Line Tool, Adobe Content Credentials JS SDK, and Adobe Content Credentials Rust SDK are affected. No specific version numbers are listed, so all current installations of these tools remain vulnerable until a vendor fix is released.
Risk and Exploitability
The CVSS score of 7.5 classifies the issue as high severity, and the EPSS score of less than 1% indicates that exploitation is unlikely but still possible. The vulnerability is not yet in CISA’s KEV catalog. Exploitation does not require user interaction, meaning an attacker who can reach the affected components could immediately extract confidential credentials or other protected data.
OpenCVE Enrichment