Description
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-07-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper input validation flaw that allows an attacker to read arbitrary files on the file system. An attacker can access sensitive files and directories outside the intended scope if a user opens a malicious file. The weakness is CWE‑20, and the primary impact is the potential exposure of confidential data, resulting in a confidentiality compromise.

Affected Systems

Adobe offers the Content Credentials Command‑Line Tool, JavaScript SDK, and Rust SDK. Any affected version of these products is vulnerable; vendors have not provided specific version ranges in the advisory.

Risk and Exploitability

The CVSS score is 5.5, indicating a moderate severity, while the EPSS score is below 1 %, implying a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attacks require user interaction: a victim must open a malicious file, making the vector social‑engineering or local file compromise rather than remote exploitation. Overall, the risk is moderate but the exploitation probability remains low.

Generated by OpenCVE AI on July 31, 2026 at 04:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Adobe Content Credentials Command‑Line Tool, JS SDK, and Rust SDK to the latest patched releases.
  • If an update is not immediately available, configure the tools to limit file access to their own directories or run them in a sandboxed environment to prevent arbitrary reads.
  • Educate users to avoid opening untrusted files that might be crafted to exploit this flaw.

Generated by OpenCVE AI on July 31, 2026 at 04:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk
Vendors & Products Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk

Wed, 15 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title CAI Content Credentials | Improper Input Validation (CWE-20)
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

Adobe Content Credentials Command-line Tool Content Credentials Js Sdk Content Credentials Rust Sdk
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-14T23:39:13.190Z

Reserved: 2026-05-21T15:28:38.140Z

Link: CVE-2026-48353

cve-icon Vulnrichment

Updated: 2026-07-14T23:34:11.541Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:36:50Z

Weaknesses
  • CWE-20

    Improper Input Validation