Description
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Published: 2026-08-11
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an integer overflow or wraparound flaw (CWE-190) that can cause the Adobe Content Credentials Command-Line Tool, JavaScript SDK, or Rust SDK to crash when numeric inputs exceed their allowed bounds. This leads to a denial‑of‑service condition, allowing an attacker to disrupt application availability without requiring user interaction.

Affected Systems

Adobe Content Credentials Command‑Line Tool, Adobe Content Credentials JavaScript SDK, and Adobe Content Credentials Rust SDK are affected. No specific version numbers are defined in the advisory, so all currently released versions may be vulnerable until an update includes the fix.

Risk and Exploitability

The CVSS score of 6.2 indicates moderate severity. The EPSS score of less than 1% suggests a low likelihood of exploitation at present, and the vulnerability is not listed in CISA's KEV catalog. Exploitation does not require user interaction. The attack vector is not explicitly disclosed; it is inferred that any entity capable of supplying inputs to the affected component could trigger the denial‑of‑service, either locally or remotely.

Generated by OpenCVE AI on August 12, 2026 at 21:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify whether an official patch exists by consulting Adobe’s security advisories and apply the patch if available.
  • If no patch is available, restrict or disable any functionality in the tool or SDK that accepts unchecked numeric input, or apply input validation to bound values before processing.
  • Observe application logs for abnormal termination events and report any suspected exploitation attempts to Adobe Security Team; consider temporarily removing the affected components until a patch is released.

Generated by OpenCVE AI on August 12, 2026 at 21:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe c2pa
Adobe c2pa-web
Adobe c2patool
CPEs cpe:2.3:a:adobe:c2pa-web:*:*:*:*:*:node.js:*:*
cpe:2.3:a:adobe:c2pa:*:*:*:*:*:rust:*:*
cpe:2.3:a:adobe:c2patool:*:*:*:*:*:*:*:*
Vendors & Products Adobe c2pa
Adobe c2pa-web
Adobe c2patool

Thu, 13 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk
Vendors & Products Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk

Tue, 11 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Title CAI Content Credentials | Integer Overflow or Wraparound (CWE-190)
Weaknesses CWE-190
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Adobe C2pa C2pa-web C2patool Content Credentials Command-line Tool Content Credentials Js Sdk Content Credentials Rust Sdk
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:34:01.334Z

Reserved: 2026-05-21T15:28:38.143Z

Link: CVE-2026-48387

cve-icon Vulnrichment

Updated: 2026-08-11T18:42:17.081Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:00.440

Modified: 2026-08-28T00:17:56.797

Link: CVE-2026-48387

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T01:45:02Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound