Description
CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Arbitrary file system read. An attacker could leverage this vulnerability to gain unauthorized read access to files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-08-11
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability described is a path traversal flaw that allows an attacker to read arbitrary files or directories outside of the intended restricted directory. This flaw can expose confidential information stored on the system. No other impact such as modification or execution is mentioned in the description.

Affected Systems

Affected products include Adobe Content Credentials Command-Line Tool, Adobe Content Credentials JavaScript SDK, and Adobe Content Credentials Rust SDK. Version details are not specified, implying that all current releases may be impacted until a patch is applied.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity issue. The EPSS score of less than 1% suggests a very low, but non-zero, likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could supply a maliciously crafted path to the affected component, exploit the path traversal without user interaction, and read files outside the intended directory. The scope change means the attacker’s read capability may extend beyond the originally restricted area.

Generated by OpenCVE AI on August 12, 2026 at 21:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Adobe Content Credentials update that removes the path traversal defect for the command line tool, JavaScript SDK, and Rust SDK.
  • Run the affected components with the least privileges required, ensuring the process cannot read system or user directories that are unrelated to its function.
  • Apply operating‑system file‑system permissions or implement sandboxing to restrict the read access granted to the SDK or tool to only the directories it needs to operate.

Generated by OpenCVE AI on August 12, 2026 at 21:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe c2pa
Adobe c2pa-web
Adobe c2patool
CPEs cpe:2.3:a:adobe:c2pa-web:*:*:*:*:*:node.js:*:*
cpe:2.3:a:adobe:c2pa:*:*:*:*:*:rust:*:*
cpe:2.3:a:adobe:c2patool:*:*:*:*:*:*:*:*
Vendors & Products Adobe c2pa
Adobe c2pa-web
Adobe c2patool

Thu, 13 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk
Vendors & Products Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk

Wed, 12 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Arbitrary file system read. An attacker could leverage this vulnerability to gain unauthorized read access to files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction. Scope is changed.
Title CAI Content Credentials | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N'}


Subscriptions

Adobe C2pa C2pa-web C2patool Content Credentials Command-line Tool Content Credentials Js Sdk Content Credentials Rust Sdk
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:33:55.158Z

Reserved: 2026-05-21T15:28:38.146Z

Link: CVE-2026-48442

cve-icon Vulnrichment

Updated: 2026-08-12T16:12:05.639Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:01.450

Modified: 2026-08-28T00:18:02.157

Link: CVE-2026-48442

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T01:45:02Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')