Description
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Published: 2026-08-25
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an integer underflow that causes the C2PA toolkit and Content Credentials Rust SDK to crash when processing certain inputs, resulting in a denial‑of‑service condition. Exploitation does not require any user interaction, making it potentially exploitable by an unauthenticated attacker who can send crafted data to the affected application.

Affected Systems

Adobe C2PA Tool and Adobe Content Credentials Rust SDK are affected. No specific vulnerable versions are listed in the advisory, so all versions running these components should be evaluated for the presence of the flaw.

Risk and Exploitability

With a CVSS score of 6.2 the flaw is considered moderate severity. The EPSS score is not reported, and the vulnerability is not listed in CISA’s KEV catalog, which suggests limited known exploitation at this time. Because the attack does not require user interaction, a remotely reachable instance of the affected software could be abused to crash the application, potentially disrupting services or availability for users.

Generated by OpenCVE AI on August 25, 2026 at 20:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Adobe support resources for a patch or updated release that addresses the integer underflow in the C2PA Tool or Content Credentials SDK.
  • Apply any available patch or upgrade to the latest released version to eliminate the underflow condition.
  • If a patch is not yet released, isolate the affected components from external inputs—restrict network exposure or employ a firewall rule to block untrusted traffic from reaching the service until remediation can be applied.

Generated by OpenCVE AI on August 25, 2026 at 20:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe c2pa
Adobe c2patool
CPEs cpe:2.3:a:adobe:c2pa:*:*:*:*:*:rust:*:*
cpe:2.3:a:adobe:c2patool:*:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe c2pa
Adobe c2patool

Tue, 25 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Title CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)
Weaknesses CWE-191
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:32:52.913Z

Reserved: 2026-08-19T11:06:46.914Z

Link: CVE-2026-76189

cve-icon Vulnrichment

Updated: 2026-08-25T18:54:25.841Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T18:18:04.673

Modified: 2026-09-01T15:14:25.443

Link: CVE-2026-76189

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T20:45:04Z

Weaknesses
  • CWE-191

    Integer Underflow (Wrap or Wraparound)