Description
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Published: 2026-08-11
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in CAI Content Credentials is an integer overflow or wraparound flaw identified as CWE-190. When an attacker supplies an input that causes the integer to wrap, the software can crash, resulting in a denial‑of‑service (DoS) condition. The impact is limited to the application process; the flaw does not enable code execution, privilege escalation, or data disclosure. The description indicates that exploitation does not require user interaction, implying that remote adversaries could trigger the failure if they can reach the vulnerable component. The weakness arises from improper validation or bounds checking of numeric values flowing through the SDK or command‑line tool. Because the flaw only causes a crash, the immediate risk to an attacker is to interrupt service availability, potentially affecting users or downstream services relying on Content Credentials.

Affected Systems

The affected parties are users of Adobe's Content Credentials Command-Line Tool, the JavaScript Software Development Kit (SDK), and the Rust SDK. Specific impacted versions are not disclosed in the current data, so all released releases that include the vulnerable code paths should be considered at risk until an official patch is posted. No vendor‑specified version list is available in the current reference material. Administrators should verify the version of each component in use and refer to Adobe's security advisory for the precise scope once it is released.

Risk and Exploitability

The CVSS score of 6.2 classifies the flaw as a moderate‑severity DoS vulnerability. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild at the time of this analysis. Adobe has not listed this issue in the CISA KEV catalog, further suggesting limited active exploitation. Attackers would need network access to the vulnerable component or the ability to supply crafted input; no user interaction is required. Given the relatively low exploit probability and the moderate severity, the risk is primarily in environments where uptime is critical and the vulnerability is not yet remediated.

Generated by OpenCVE AI on August 12, 2026 at 21:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe update for the Content Credentials Command-Line Tool, JS SDK, or Rust SDK that fixes the integer overflow.
  • If an immediate patch is unavailable, consider updating the affected component to the newest release once the vendor publishes a fix.
  • Restrict network exposure to the vulnerable component or gateway to untrusted traffic, limiting the attack surface for control‑plane data that could trigger the overflow.
  • Enable detailed logging on the affected services and monitor for abnormal termination or crash events that may signal exploitation attempts.

Generated by OpenCVE AI on August 12, 2026 at 21:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe c2pa
Adobe c2pa-web
Adobe c2patool
CPEs cpe:2.3:a:adobe:c2pa-web:*:*:*:*:*:node.js:*:*
cpe:2.3:a:adobe:c2pa:*:*:*:*:*:rust:*:*
cpe:2.3:a:adobe:c2patool:*:*:*:*:*:*:*:*
Vendors & Products Adobe c2pa
Adobe c2pa-web
Adobe c2patool

Thu, 13 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk
Vendors & Products Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk

Tue, 11 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Title CAI Content Credentials | Integer Overflow or Wraparound (CWE-190)
Weaknesses CWE-190
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Adobe C2pa C2pa-web C2patool Content Credentials Command-line Tool Content Credentials Js Sdk Content Credentials Rust Sdk
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:34:16.390Z

Reserved: 2026-05-21T15:28:38.146Z

Link: CVE-2026-48445

cve-icon Vulnrichment

Updated: 2026-08-11T18:42:46.984Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:01.820

Modified: 2026-08-28T00:18:04.177

Link: CVE-2026-48445

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T01:45:02Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound