Description
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Published: 2026-07-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CAI Content Credentials components contain an Improper Input Validation flaw identified as CWE‑20 that allows an attacker to craft malicious input and cause the application to crash. The resulting crash ends the service, leading to a denial‑of‑service condition that cannot be recovered without application restart.

Affected Systems

Adobe’s Content Credentials Command‑Line Tool, the JavaScript SDK, and the Rust SDK are impacted. The advisory does not list affected versions, so any deployment of these components may be susceptible until a patch is applied.

Risk and Exploitability

The CVSS score of 7.5 marks this vulnerability as high severity. An EPSS score of < 1 % indicates that exploitation is considered unlikely, but it is still possible. No active exploits are listed in the KEV catalog. The vulnerability does not require user interaction, making it potentially exploitable remotely by sending crafted input to the affected components.

Generated by OpenCVE AI on July 31, 2026 at 04:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Adobe Content Credentials Command‑Line Tool, JS SDK, and Rust SDK to the latest versions available in the Adobe Security Advisory.
  • Add strict input validation in any code that processes data for the Content Credentials components, ensuring only expected formats are accepted.
  • Restrict exposure of the Content Credentials services to trusted networks or environments, using firewall rules or role‑based access controls to limit who can send input to the vulnerable components.

Generated by OpenCVE AI on July 31, 2026 at 04:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk
Vendors & Products Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk

Wed, 15 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Title CAI Content Credentials | Improper Input Validation (CWE-20)
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Adobe Content Credentials Command-line Tool Content Credentials Js Sdk Content Credentials Rust Sdk
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-14T23:39:12.490Z

Reserved: 2026-05-21T15:28:38.140Z

Link: CVE-2026-48351

cve-icon Vulnrichment

Updated: 2026-07-14T23:34:02.559Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:36:43Z

Weaknesses
  • CWE-20

    Improper Input Validation