Description
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.
Published: 2026-07-14
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper input validation flaw in Adobe Content Credentials allows an attacker to bypass security checks and gain write access without user interaction. The vulnerability permits unauthorized modification of protected data or configuration, potentially compromising system integrity and enabling further lateral movement.

Affected Systems

The flaw affects Adobe Content Credentials Command-Line Tool, Adobe Content Credentials JS SDK, and Adobe Content Credentials Rust SDK. No specific affected versions are listed, so all exposed instances of these components should be considered vulnerable until a vendor update is applied.

Risk and Exploitability

The CVSS score of 6.8 indicates a moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation, and the vulnerability is not currently listed in CISA's KEV catalog. Exploitation does not require user interaction and could be performed remotely against services that use the vulnerable SDKs or command‑line tool. The impact is that an attacker could write or modify data, potentially escaping restricted namespaces or environments.

Generated by OpenCVE AI on July 31, 2026 at 04:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest available version of Adobe Content Credentials that contains the input validation fix
  • Restrict write permissions on critical files and directories to only trusted users and processes
  • Enable detailed logging and monitoring for unexpected write operations to detect potential exploitation attempts

Generated by OpenCVE AI on July 31, 2026 at 04:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk
Vendors & Products Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk

Wed, 15 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.
Title CAI Content Credentials | Improper Input Validation (CWE-20)
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N'}


Subscriptions

Adobe Content Credentials Command-line Tool Content Credentials Js Sdk Content Credentials Rust Sdk
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-14T23:39:12.350Z

Reserved: 2026-05-21T15:28:38.136Z

Link: CVE-2026-48312

cve-icon Vulnrichment

Updated: 2026-07-14T23:34:00.543Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:36:41Z

Weaknesses
  • CWE-20

    Improper Input Validation