Description
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Published: 2026-08-25
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

This vulnerability arises from improper input validation within CAI Content Credentials, allowing an attacker to supply crafted data that causes the application to crash. The resulting denial‑of‑service prevents legitimate users from accessing the service until it is restarted, potentially impacting availability for enterprises relying on content authentication.

Affected Systems

Adobe C2PA Tool and Adobe Content Credentials Rust SDK are the affected products. The issue is cataloged for the relevant Adobe applications that use these components to verify digital content authenticity, but no specific version range is listed in the provided data.

Risk and Exploitability

The CVSS score of 7.5 classifies the vulnerability as high severity. The EPSS score is not available, indicating that up‑to‑date exploitation probability data is lacking. This issue is not yet listed in the CISA KEV catalog. Exploitation does not require user interaction and can be performed remotely by sending malformed input to the vulnerable component. The lack of a publicly known patch or workaround suggests that the risk hinges on whether the affected system is exposed to untrusted data streams.

Generated by OpenCVE AI on August 25, 2026 at 20:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security update or patch released by Adobe for the C2PA Tool or Content Credentials Rust SDK.
  • Restrict or sanitize all external inputs to the SDK by implementing strict validation and whitelisting of acceptable data formats.
  • Implement monitoring for sudden crashes or unhandled exceptions in the application that could indicate exploitation attempts.

Generated by OpenCVE AI on August 25, 2026 at 20:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe c2pa
Adobe c2patool
CPEs cpe:2.3:a:adobe:c2pa:*:*:*:*:*:rust:*:*
cpe:2.3:a:adobe:c2patool:*:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe c2pa
Adobe c2patool

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Title CAI Content Credentials | Improper Input Validation (CWE-20)
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:32:46.229Z

Reserved: 2026-08-06T16:40:07.109Z

Link: CVE-2026-71443

cve-icon Vulnrichment

Updated: 2026-08-27T16:16:11.067Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T18:18:01.490

Modified: 2026-09-01T15:14:45.107

Link: CVE-2026-71443

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T20:45:04Z

Weaknesses
  • CWE-20

    Improper Input Validation