Impact
CAI Content Credentials suffers an Improper Input Validation flaw that allows an attacker to read arbitrary files from the file system. The vulnerability, linked to CWE-20, can be triggered when a user opens a specially crafted file. Although no remote code execution or denial of service is described, the flaw permits access to sensitive files and directories beyond the intended access scope, potentially exposing confidential data and system secrets.
Affected Systems
Adobe products affected are the Adobe C2PA Tool and the Adobe Content Credentials Rust SDK. No explicit version ranges are provided in the CVE entry, and therefore the scope of versions remains unclear.
Risk and Exploitability
The CVSS score of 5.5 indicates a medium severity. EPSS is not available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. The attack requires user interaction; a victim must open a malicious file for the flaw to be exercised. If a user’s system trusts the file or the application processes it without additional verification, the attacker can read files otherwise protected by file system permissions.
OpenCVE Enrichment