Description
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-08-25
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality breach
Action: Patch ASAP
AI Analysis

Impact

CAI Content Credentials suffers an Improper Input Validation flaw that allows an attacker to read arbitrary files from the file system. The vulnerability, linked to CWE-20, can be triggered when a user opens a specially crafted file. Although no remote code execution or denial of service is described, the flaw permits access to sensitive files and directories beyond the intended access scope, potentially exposing confidential data and system secrets.

Affected Systems

Adobe products affected are the Adobe C2PA Tool and the Adobe Content Credentials Rust SDK. No explicit version ranges are provided in the CVE entry, and therefore the scope of versions remains unclear.

Risk and Exploitability

The CVSS score of 5.5 indicates a medium severity. EPSS is not available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. The attack requires user interaction; a victim must open a malicious file for the flaw to be exercised. If a user’s system trusts the file or the application processes it without additional verification, the attacker can read files otherwise protected by file system permissions.

Generated by OpenCVE AI on August 25, 2026 at 20:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the vendor’s latest patch for Adobe C2PA Tool or Adobe Content Credentials Rust SDK as soon as it becomes available
  • Restrict the application’s privileges or disable it when not needed to limit file access
  • Educate users to avoid opening unknown or suspicious files and to enable content warnings in the application settings

Generated by OpenCVE AI on August 25, 2026 at 20:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe c2pa
Adobe c2patool
CPEs cpe:2.3:a:adobe:c2pa:*:*:*:*:*:rust:*:*
cpe:2.3:a:adobe:c2patool:*:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe c2pa
Adobe c2patool

Wed, 26 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title CAI Content Credentials | Improper Input Validation (CWE-20)
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:32:38.080Z

Reserved: 2026-08-19T11:09:11.113Z

Link: CVE-2026-76198

cve-icon Vulnrichment

Updated: 2026-08-26T14:06:12.398Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T18:18:05.253

Modified: 2026-09-01T15:14:12.980

Link: CVE-2026-76198

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T20:45:04Z

Weaknesses
  • CWE-20

    Improper Input Validation