Description
CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Published: 2026-08-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a NULL Pointer Dereference that causes the application to crash, resulting in a denial‑of‑service. The flaw exists in Adobe Content Credentials components, and its exploitation does not require user interaction.

Affected Systems

Adobe: Content Credentials Command-Line Tool, Adobe: Content Credentials JS SDK, Adobe: Content Credentials Rust SDK. No version information is provided in the advisory; therefore the impact may apply to all released versions until a patch is available.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, while an EPSS score of less than 1% suggests exploitation is unlikely at present, and the vulnerability is not listed in CISA’s KEV catalog. The description states no user interaction is required, so the likely attack vector is either remote or local exploitation via malformed input to the CLI or SDK. A practitioner should consider that the flaw can be triggered by an attacker supplying crafted data to the affected components, but no evidence of privilege escalation or data exfiltration is provided.

Generated by OpenCVE AI on August 12, 2026 at 20:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Adobe Content Credentials Command-Line Tool, JS SDK, and Rust SDK to the latest versions that contain the fix.
  • If an update is pending or unavailable, disable or restrict the execution of the affected components until a patch is applied.
  • Continuously monitor system logs and application metrics for abnormal crashes or denial‑of‑service events linked to Content Credentials.

Generated by OpenCVE AI on August 12, 2026 at 20:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe c2pa
Adobe c2pa-web
Adobe c2patool
CPEs cpe:2.3:a:adobe:c2pa-web:*:*:*:*:*:node.js:*:*
cpe:2.3:a:adobe:c2pa:*:*:*:*:*:rust:*:*
cpe:2.3:a:adobe:c2patool:*:*:*:*:*:*:*:*
Vendors & Products Adobe c2pa
Adobe c2pa-web
Adobe c2patool

Thu, 13 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk
Vendors & Products Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk

Tue, 11 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Title CAI Content Credentials | NULL Pointer Dereference (CWE-476)
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Adobe C2pa C2pa-web C2patool Content Credentials Command-line Tool Content Credentials Js Sdk Content Credentials Rust Sdk
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:34:09.878Z

Reserved: 2026-05-21T15:28:38.146Z

Link: CVE-2026-48438

cve-icon Vulnrichment

Updated: 2026-08-11T18:41:25.550Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:01.087

Modified: 2026-08-28T00:18:01.703

Link: CVE-2026-48438

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T03:30:03Z

Weaknesses