CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Adobe
Adobe c2pa Adobe c2patool |
|
| CPEs | cpe:2.3:a:adobe:c2pa:*:*:*:*:*:rust:*:* cpe:2.3:a:adobe:c2patool:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Adobe
Adobe c2pa Adobe c2patool |
Wed, 26 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Title | CAI Content Credentials | Improper Input Validation (CWE-20) | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: adobe
Published: 2026-08-25T17:31:26.360Z
Updated: 2026-08-27T22:32:38.080Z
Reserved: 2026-08-19T11:09:11.113Z
Link: CVE-2026-76198
Updated: 2026-08-26T14:06:12.398Z
Status : Analyzed
Published: 2026-08-25T18:18:05.253
Modified: 2026-09-01T15:14:12.980
Link: CVE-2026-76198
No data.