Description
CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.
Published: 2026-08-11
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CAI Content Credentials is affected by a path traversal flaw that lets an attacker read files outside the intended directory. The vulnerability occurs when a user processes a crafted pathname and can result in arbitrary file system reads, potentially exposing sensitive application or system files. The impact is strictly confidentiality loss; there is no evidence of code execution or privilege escalation in the supplied description.

Affected Systems

Adobe Content Credentials Command‑Line Tool, Adobe Content Credentials JavaScript SDK, and Adobe Content Credentials Rust SDK are all affected. No specific version range is provided in the advisory, so any installation of these components may be vulnerable until updated.

Risk and Exploitability

The CVSS score of 5.5 places the issue in the moderate severity range. EPSS is listed as less than 1%, indicating a very low probability of exploitation as of now, and the vulnerability is not in the CISA KEV catalog. However, because exploitation requires a victim to visit a maliciously crafted URL or interact with a compromised web page, the risk is tied to user behavior. If users are exposed to phishing or compromised sites, the path traversal could be triggered. Mitigation of the flaw is essential to prevent possible confidential data exposure.

Generated by OpenCVE AI on August 12, 2026 at 21:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Adobe Security Advisory APSB26-111 patch or upgrade to a version of the Content Credentials tooling that includes the path traversal fix.
  • Ensure that the updated Command‑Line Tool, JavaScript SDK, and Rust SDK are deployed and that no older, vulnerable versions remain in use.
  • Configure the application to validate and normalize any user‑supplied file paths, restricting reads strictly to the intended directory tree.

Generated by OpenCVE AI on August 12, 2026 at 21:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe c2pa
Adobe c2pa-web
Adobe c2patool
CPEs cpe:2.3:a:adobe:c2pa-web:*:*:*:*:*:node.js:*:*
cpe:2.3:a:adobe:c2pa:*:*:*:*:*:rust:*:*
cpe:2.3:a:adobe:c2patool:*:*:*:*:*:*:*:*
Vendors & Products Adobe c2pa
Adobe c2pa-web
Adobe c2patool

Thu, 13 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk
Vendors & Products Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk

Wed, 12 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.
Title CAI Content Credentials | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

Adobe C2pa C2pa-web C2patool Content Credentials Command-line Tool Content Credentials Js Sdk Content Credentials Rust Sdk
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:34:13.147Z

Reserved: 2026-05-21T15:28:38.146Z

Link: CVE-2026-48446

cve-icon Vulnrichment

Updated: 2026-08-12T14:16:04.193Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:01.943

Modified: 2026-08-28T00:18:04.390

Link: CVE-2026-48446

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T01:45:02Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')