Description
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Published: 2026-08-25
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from improper input validation within CAI Content Credentials, allowing an attacker to supply crafted data that causes the application to crash. The resulting denial‑of‑service prevents legitimate users from accessing the service until it is restarted, potentially impacting availability for enterprises relying on content authentication.

Affected Systems

Adobe C2PA Tool and Adobe Content Credentials Rust SDK are the affected products. The issue is cataloged for the relevant Adobe applications that use these components to verify digital content authenticity, but no specific version range is listed in the provided data.

Risk and Exploitability

The CVSS score of 7.5 classifies the vulnerability as high severity. The EPSS score is not available, indicating that up‑to‑date exploitation probability data is lacking. This issue is not yet listed in the CISA KEV catalog. Exploitation does not require user interaction and can be performed remotely by sending malformed input to the vulnerable component. The lack of a publicly known patch or workaround suggests that the risk hinges on whether the affected system is exposed to untrusted data streams.

Generated by OpenCVE AI on August 25, 2026 at 19:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security update or patch released by Adobe for the C2PA Tool or Content Credentials Rust SDK.
  • Restrict or sanitize all external inputs to the SDK by implementing strict validation and whitelisting of acceptable data formats.
  • Implement monitoring for sudden crashes or unhandled exceptions in the application that could indicate exploitation attempts.

Generated by OpenCVE AI on August 25, 2026 at 19:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Title CAI Content Credentials | Improper Input Validation (CWE-20)
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-25T17:31:29.904Z

Reserved: 2026-08-06T16:40:07.109Z

Link: CVE-2026-71443

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T18:18:01.490

Modified: 2026-08-25T18:18:01.490

Link: CVE-2026-71443

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T19:15:05Z

Weaknesses
  • CWE-20

    Improper Input Validation