CVE-2026-48295

HIGH

CAI Content Credentials | Insufficiently Protected Credentials (CWE-522)

Title source: cna
STIX 2.1

Description

CAI Content Credentials is affected by an Insufficiently Protected Credentials vulnerability that could result in disclosure of sensitive information. An attacker could leverage this vulnerability to gain unauthorized read access. Exploitation of this issue does not require user interaction.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0039
EPSS Percentile 31.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-522
Status published
Products (9)
adobe/c2pa < 0.84.0
adobe/c2pa-web < 0.7.0
adobe/c2patool < 0.17.0
Adobe/Content Credentials Command-Line Tool < c2patool-v0.16.5
Adobe/Content Credentials Command-Line Tool c2patool-v0.26.65
Adobe/Content Credentials JS SDK < @contentauth/[email protected]
Adobe/Content Credentials JS SDK @contentauth/[email protected]
Adobe/Content Credentials Rust SDK < c2pa-v0.84.0
Adobe/Content Credentials Rust SDK c2pa-v0.85.2
Published Jul 14, 2026
Tracked Since Jul 15, 2026