Impact
Improper Input Validation in CAI Content Credentials allows an attacker to bypass built‑in security controls, potentially granting write access to protected resources. The flaw resides in how the tool processes input, and without proper validation it can accept maliciously crafted data that is treated as legitimate. This produces a direct impact on data integrity by permitting the tampering or creation of files that should be write‑protected.
Affected Systems
Adobe Content Credentials Command-Line Tool and Adobe Content Credentials Rust SDK are affected. No specific version numbers are disclosed in the advisory, so any installed instance of these products should be considered susceptible until a vendor update is released.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. Exploitation requires user interaction: a victim must visit a malicious URL or interact with a compromised web page containing crafted input. The vulnerability is not listed in CISA’s KEV catalog, and no EPSS score is available, making it unclear how frequently it is being targeted. Nonetheless, because the flaw enables a bypass of security measures, the potential impact on confidentiality and integrity warrants attention.
OpenCVE Enrichment