Description
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Published: 2026-08-25
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Content Credentials, including the C2PA Tool and the Rust SDK, contains an integer underflow vulnerability that can cause the application to crash when malformed input is processed, resulting in a denial-of-service condition. The flaw allows an attacker to trigger a wraparound in signed or unsigned arithmetic during credential verification, leading to an abrupt application termination. This impact is purely availability loss; confidentiality or integrity are not directly compromised.

Affected Systems

The vulnerability impacts Adobe’s C2PA Tool and the Adobe Content Credentials Rust SDK. No specific affected versions are listed, so all installations of these products remain potentially vulnerable until a patch is applied or the feature is disabled.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity issue. Exploitation does not require user interaction, and the attack can be performed remotely by providing crafted credential data to the affected process. While the EPSS score is currently unavailable, the absence of KEV listing suggests no known active exploitation. Nevertheless, the high severity makes timely mitigation important.

Generated by OpenCVE AI on August 25, 2026 at 20:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Adobe C2PA Tool and the Adobe Content Credentials Rust SDK to the latest patched versions once they become available.
  • If an immediate patch is not possible, disable any functionality that processes external credentials or isolate the affected component to prevent the underflow from affecting other parts of the application.
  • Monitor Adobe security advisories for updates to this vulnerability and apply them as soon as they are released.
  • Implement input validation to ensure all integer values derived from external sources are checked against overflow or underflow before use, which provides a defensive measure until a vendor fix is deployed.

Generated by OpenCVE AI on August 25, 2026 at 20:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Title CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)
Weaknesses CWE-191
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-25T17:46:01.366Z

Reserved: 2026-08-06T16:40:07.109Z

Link: CVE-2026-71442

cve-icon Vulnrichment

Updated: 2026-08-25T17:44:35.803Z

cve-icon NVD

Status : Received

Published: 2026-08-25T18:18:01.333

Modified: 2026-08-25T18:18:01.333

Link: CVE-2026-71442

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T20:45:04Z

Weaknesses
  • CWE-191

    Integer Underflow (Wrap or Wraparound)