Description
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Published: 2026-08-25
Score: 6.2 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an integer underflow that causes the C2PA toolkit and Content Credentials Rust SDK to crash when processing certain inputs, resulting in a denial‑of‑service condition. Exploitation does not require any user interaction, making it potentially exploitable by an unauthenticated attacker who can send crafted data to the affected application.

Affected Systems

Adobe C2PA Tool and Adobe Content Credentials Rust SDK are affected. No specific vulnerable versions are listed in the advisory, so all versions running these components should be evaluated for the presence of the flaw.

Risk and Exploitability

With a CVSS score of 6.2 the flaw is considered moderate severity. The EPSS score is not reported, and the vulnerability is not listed in CISA’s KEV catalog, which suggests limited known exploitation at this time. Because the attack does not require user interaction, a remotely reachable instance of the affected software could be abused to crash the application, potentially disrupting services or availability for users.

Generated by OpenCVE AI on August 25, 2026 at 19:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Adobe support resources for a patch or updated release that addresses the integer underflow in the C2PA Tool or Content Credentials SDK.
  • Apply any available patch or upgrade to the latest released version to eliminate the underflow condition.
  • If a patch is not yet released, isolate the affected components from external inputs—restrict network exposure or employ a firewall rule to block untrusted traffic from reaching the service until remediation can be applied.

Generated by OpenCVE AI on August 25, 2026 at 19:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Title CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)
Weaknesses CWE-191
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-25T18:54:34.647Z

Reserved: 2026-08-19T11:06:46.914Z

Link: CVE-2026-76189

cve-icon Vulnrichment

Updated: 2026-08-25T18:54:25.841Z

cve-icon NVD

Status : Received

Published: 2026-08-25T18:18:04.673

Modified: 2026-08-25T19:16:53.900

Link: CVE-2026-76189

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T19:15:05Z

Weaknesses
  • CWE-191

    Integer Underflow (Wrap or Wraparound)