Impact
An improper input validation flaw in Adobe Content Credentials allows an attacker to bypass security checks and gain write access without user interaction. The vulnerability permits unauthorized modification of protected data or configuration, potentially compromising system integrity and enabling further lateral movement.
Affected Systems
The flaw affects Adobe Content Credentials Command-Line Tool, Adobe Content Credentials JS SDK, and Adobe Content Credentials Rust SDK. No specific affected versions are listed, so all exposed instances of these components should be considered vulnerable until a vendor update is applied.
Risk and Exploitability
The CVSS score of 6.8 indicates a moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation, and the vulnerability is not currently listed in CISA's KEV catalog. Exploitation does not require user interaction and could be performed remotely against services that use the vulnerable SDKs or command‑line tool. The impact is that an attacker could write or modify data, potentially escaping restricted namespaces or environments.
OpenCVE Enrichment