Description
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Published: 2026-07-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The problem is an Improper Input Validation flaw (CWE‑20) that allows an attacker to supply malformed data to the Adobe Content Credentials Command‑Line Tool, JS SDK, or Rust SDK. The bad input causes the targeted component to crash, which results in a denial‑of‑service condition for its users. No data leakage or remote code execution is achievable based on the description provided.

Affected Systems

Adobe Content Credentials Command‑Line Tool, Adobe Content Credentials JS SDK, and Adobe Content Credentials Rust SDK are impacted. Version specifics are not listed, so all available releases up to the present should be reviewed for the presence of the flaw.

Risk and Exploitability

The CVSS score of 7.5 signals high severity, while the EPSS score of less than 1% indicates a low likelihood of active exploitation. The vulnerability is not in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is remote, since the flaw is triggered by malformed input that can be supplied without user interaction, making exposed deployments vulnerable to operational disruption.

Generated by OpenCVE AI on July 31, 2026 at 04:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the most recent Adobe Content Credentials release that includes the input‑validation fix.
  • If no patch has yet been released, limit the network exposure of the affected components or disable unused input interfaces to reduce attack surface.
  • Apply application‑level input validation to any data forwarded to the Content Credentials components, providing a temporary safeguard until a vendor update is available.

Generated by OpenCVE AI on July 31, 2026 at 04:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk
Vendors & Products Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk

Wed, 15 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Title CAI Content Credentials | Improper Input Validation (CWE-20)
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Adobe Content Credentials Command-line Tool Content Credentials Js Sdk Content Credentials Rust Sdk
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-14T23:39:13.057Z

Reserved: 2026-05-21T15:28:38.140Z

Link: CVE-2026-48352

cve-icon Vulnrichment

Updated: 2026-07-14T23:34:09.488Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:36:49Z

Weaknesses
  • CWE-20

    Improper Input Validation