Description
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Published: 2026-07-14
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An integer underflow flaw in Adobe CAI Content Credentials causes an unsigned value to wrap, which triggers a crash path during input handling. The crash leads to a denial‑of‑service condition. The advisory does not state any compromise of confidentiality or integrity, so the impact is limited to availability.

Affected Systems

Adobe Content Credentials Command‑Line Tool, Adobe Content Credentials JavaScript SDK, and Adobe Content Credentials Rust SDK are affected. Version information is not disclosed in the advisory; therefore any current instance of these components could be vulnerable.

Risk and Exploitability

The CVSS score of 6.2 classifies the issue as moderate severity. The EPSS score of less than 1% indicates a very low probability of exploitation. It is not listed in the CISA KEV catalog. Exploitation does not require user interaction; the likely attack surface involves supplying malformed data to the SDK or tool, although explicit details are not provided.

Generated by OpenCVE AI on July 31, 2026 at 04:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s latest patch or upgrade the Content Credentials Command‑Line Tool, JavaScript SDK, and Rust SDK to the most recent security‑released versions.
  • If a patch is unavailable, isolate or temporarily remove the vulnerable components from the environment to prevent exploitation.
  • Validate numeric inputs to ensure they stay within expected bounds before they are passed to the SDK or tool to avoid underflow.

Generated by OpenCVE AI on July 31, 2026 at 04:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk
Vendors & Products Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk

Wed, 15 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Title CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)
Weaknesses CWE-191
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Adobe Content Credentials Command-line Tool Content Credentials Js Sdk Content Credentials Rust Sdk
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-14T23:39:12.913Z

Reserved: 2026-05-21T15:28:38.135Z

Link: CVE-2026-48298

cve-icon Vulnrichment

Updated: 2026-07-14T23:34:07.952Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:36:47Z

Weaknesses
  • CWE-191

    Integer Underflow (Wrap or Wraparound)