Description
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.
Severity (CVSS)
| Base score | 6.8 |
|---|---|
| Severity | Medium |
| Version | CVSS 3.1 |
| Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N |
| Provided by | CNA |
Weaknesses
- CWE-20 — Improper Input Validation (CWE-20)
Affected products
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Content Credentials Rust SDK | 0 to <=c2pa-v0.84.0; c2pa-v0.85.2 |
| Adobe | Content Credentials Command-Line Tool | 0 to <=c2patool-v0.16.5; c2patool-v0.26.65 |
| Adobe | Content Credentials JS SDK | 0 to <=@contentauth/c2pa-web@0.7.0; @contentauth/c2pa-web@0.9.0 |
References
Generated from the official CVE List on 15 Jul 2026 07:06 UTC.