CVE-2026-71390
published 2026-08-11CVE-2026-71390: CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage…
PriorityP419medium4CVSS 3.1
AVLACLPRNUINSUCNILAN
EPSS
0.15%
5.2th percentile
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue does not require user interaction.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | c2pa | < 0.90.6 | 0.90.6 |
| adobe | c2pa-web | < 0.12.1 | 0.12.1 |
| adobe | c2patool | < 0.27.6 | 0.27.6 |
| adobe | content_credentials_command-line_tool | <= c2patool-v0.27.5 | — |
| adobe | content_credentials_js_sdk | <= @contentauth/[email protected] | — |
| adobe | content_credentials_rust_sdk | <= c2pa-v0.90.5 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Adobe Command-Line Tool/JS SDK/Rust SDK input validation
vuldb·2026-08-12·CVSS 4.0
CVE-2026-71390 [MEDIUM] Adobe Command-Line Tool/JS SDK/Rust SDK input validation
A vulnerability has been found in Adobe Command-Line Tool, JS SDK and Rust SDK and classified as critical. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in improper input validation.
This vulnerability is cataloged as CVE-2026-71390. It is possible to initiate the attack remotely. There is no exploit available.
GHSA
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass.
ghsa_unreviewed·2026-08-11
CVE-2026-71390 [MEDIUM] CWE-20 CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass.
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue does not require user interaction.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-11
Published