Description
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Published: 2026-07-14
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in CAI Content Credentials, where improper input validation can cause an application crash and result in a denial‑of‑service. Exploitation does not require user interaction, allowing an attacker to trigger the fault simply by supplying crafted input.

Affected Systems

Adobe Content Credentials Command‑Line Tool, Adobe Content Credentials JS SDK, and Adobe Content Credentials Rust SDK are affected. The advisory does not list specific version numbers, so all releases may be is applied.

Risk and Exploitability

The CVSS score of 6.2 indicates a moderate severity. The EPSS score, less than 1%, suggests that the likelihood of exploitation at present is low. Based on the description, it is inferred that since no user interaction is required, any actor who can supply crafted input may potentially trigger the crash; therefore both local and remote actors could exploit this vulnerability, although the risk remains moderate and this issue is not yet listed in the CISA KEV catalog.

Generated by OpenCVE AI on July 31, 2026 at 04:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Adobe Content Credentials updates that specifically address the improper input validation flaw for the Command‑Line Tool, JS SDK, and Rust SDK.
  • Add explicit validation checks to any data supplied to the CAI Content Credentials components, ensuring only well‑formed tokens and artifacts are processed.
  • Enable crash‑dump collection and alerting for the affected components so that denial‑of‑service incidents are detected and responded to promptly.
  • Stay informed of Adobe security advisories and apply updates promptly as new patches become available.

Generated by OpenCVE AI on July 31, 2026 at 04:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk
Vendors & Products Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk

Wed, 15 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Title CAI Content Credentials | Improper Input Validation (CWE-20)
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Adobe Content Credentials Command-line Tool Content Credentials Js Sdk Content Credentials Rust Sdk
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-14T23:39:12.634Z

Reserved: 2026-05-21T15:28:38.136Z

Link: CVE-2026-48302

cve-icon Vulnrichment

Updated: 2026-07-14T23:34:04.862Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:36:44Z

Weaknesses
  • CWE-20

    Improper Input Validation