Description
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.
Published: 2026-08-11
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an Improper Input Validation flaw that allows an attacker to bypass security controls and gain unauthorized write access. The weakness, classified as CWE-20, can be exploited by providing malformed input that the system fails to validate correctly. If successful, the attacker can modify or create data beyond the intended permissions, potentially compromising data integrity and availability.

Affected Systems

Adobe Content Credentials Command-Line Tool, Adobe Content Credentials JavaScript SDK, and Adobe Content Credentials Rust SDK are affected. No specific version numbers are listed, so all current releases of these components are considered vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The vulnerability is not currently listed in CISA’s KEV catalog. Exploitation requires user interaction; a victim must open a maliciously crafted URL or interact with a compromised web page. Thus the attack surface is limited to phishing or social engineering vectors and is not remotely exploitable without user action.

Generated by OpenCVE AI on August 12, 2026 at 21:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest update for Adobe Content Credentials as released in the Adobe Security Advisory.
  • If a patch is unavailable, configure the application to reject all untrusted input by enforcing strict validation and only accepting content from trusted, signed sources.
  • Implement least‑privilege file write permissions and monitor system logs for unauthorized write activity.
  • Use a web filtering solution or Web Application Firewall to block access to known malicious URLs that may exploit this flaw.

Generated by OpenCVE AI on August 12, 2026 at 21:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe c2pa
Adobe c2pa-web
Adobe c2patool
CPEs cpe:2.3:a:adobe:c2pa-web:*:*:*:*:*:node.js:*:*
cpe:2.3:a:adobe:c2pa:*:*:*:*:*:rust:*:*
cpe:2.3:a:adobe:c2patool:*:*:*:*:*:*:*:*
Vendors & Products Adobe c2pa
Adobe c2pa-web
Adobe c2patool

Thu, 13 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk
Vendors & Products Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk

Tue, 11 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.
Title CAI Content Credentials | Improper Input Validation (CWE-20)
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}


Subscriptions

Adobe C2pa C2pa-web C2patool Content Credentials Command-line Tool Content Credentials Js Sdk Content Credentials Rust Sdk
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:34:16.022Z

Reserved: 2026-05-21T15:28:38.146Z

Link: CVE-2026-48436

cve-icon Vulnrichment

Updated: 2026-08-11T17:50:11.237Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:00.830

Modified: 2026-08-28T00:18:01.480

Link: CVE-2026-48436

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T04:45:02Z

Weaknesses
  • CWE-20

    Improper Input Validation