CVE-2026-48312
published 2026-07-14CVE-2026-48312: CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage…
PriorityP434medium6.8CVSS 3.1
AVLACLPRNUINSUCLIHAN
EPSS
0.16%
5.4th percentile
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | c2pa | <= 0.84.0 | — |
| adobe | c2pa-web | <= 0.7.0 | — |
| adobe | c2patool | <= 0.17.0 | — |
| adobe | content_credentials_command-line_tool | <= c2patool-v0.16.5 | — |
| adobe | content_credentials_js_sdk | <= @contentauth/[email protected] | — |
| adobe | content_credentials_rust_sdk | <= c2pa-v0.84.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Adobe Content Credentials Rust SDK input validation
vuldb·2026-07-15·CVSS 6.8
CVE-2026-48312 [MEDIUM] Adobe Content Credentials Rust SDK input validation
A vulnerability was found in Adobe Content Credentials Rust SDK, Content Credentials Command-Line Tool and Content Credentials JS SDK. It has been classified as problematic. This issue affects some unknown processing of the component Content Credentials. The manipulation leads to improper input validation.
This vulnerability is uniquely identified as CVE-2026-48312. The attack is possible to be carried out remotely. No exploit exists.
GHSA
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass.
ghsa_unreviewed·2026-07-15
CVE-2026-48312 [MEDIUM] CWE-20 CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass.
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-14
Published