Description
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Published: 2026-07-14
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe’s CAI Content Credentials contains an Integer Overflow or Wraparound flaw (CWE‑190) that can allow an attacker to crash the application, resulting in a denial‑of‑service condition without requiring any user interaction.

Affected Systems

The vulnerability affects Adobe Content Credentials Command‑Line Tool, Adobe Content Credentials JS SDK, and Adobe Content Credentials Rust SDK.

Risk and Exploitability

The CVSS score of 6.2 indicates moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation. It is not listed in CISA KEV, so there is no evidence of widespread active exploitation. The likely attack vector is via malformed or crafted input that triggers the integer wraparound; this inference comes from the description stating that exploitation does not require user interaction.

Generated by OpenCVE AI on July 31, 2026 at 04:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or update released by Adobe for the affected Content Credentials components.
  • Implement input validation to reject or sanitize numeric values that could cause overflow as a temporary countermeasure.
  • Monitor application logs for abrupt termination or crash events and alert on possible denial‑of‑service attempts.

Generated by OpenCVE AI on July 31, 2026 at 04:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk
Vendors & Products Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk

Wed, 15 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Title CAI Content Credentials | Integer Overflow or Wraparound (CWE-190)
Weaknesses CWE-190
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Adobe Content Credentials Command-line Tool Content Credentials Js Sdk Content Credentials Rust Sdk
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-14T23:39:12.774Z

Reserved: 2026-05-21T15:28:38.140Z

Link: CVE-2026-48354

cve-icon Vulnrichment

Updated: 2026-07-14T23:34:06.474Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:36:46Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound