Impact
An Improper Input Validation flaw can allow a malicious actor to bypass security controls and obtain restricted write permissions. The flaw is present in the CAI Content Credentials system and is categorized as CWE‑20. Attackers could leverage the vulnerability to insert crafted requests that the system fails to sanitize, leading to a breach of the intended access boundaries.
Affected Systems
Adobe’s Content Credentials Command‑Line Tool and the Adobe Content Credentials Rust SDK are affected. No further vendor or product details are provided beyond these two software components.
Risk and Exploitability
The vulnerability has a CVSS score of 4.3, indicating moderate severity. No EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires user interaction; a victim must access a maliciously crafted URL or a compromised web page. This limits the likelihood of remote, automated exploitation but still poses a risk to users who are susceptible to social engineering or web content attacks.
OpenCVE Enrichment