Adobe Content Credentials Insufficiently Protected Credentials Vulnerability Allowing Unauthorized Read Access

Vulnerability

A vulnerability in Adobe Content Credentials SDKs, including the Rust SDK, Command-Line Tool, and JS SDK, prior to the latest versions, allows for unauthorized read access to sensitive information. This issue arises from insufficiently protected credentials, and exploitation does not require user interaction.

Impact

Exploitation of this vulnerability could lead to unauthorized read access of sensitive information.

Remediation

Users are advised to update to the latest versions of the affected SDKs. The updated versions are: Content Credentials Rust SDK (c2pa-v0.85.2), Content Credentials Command-Line Tool (c2patool-v0.26.65), and Content Credentials JS SDK (@contentauth/c2pa-web@0.9.0).

Added: Jul 15, 2026, 3:54 AM
Updated: Jul 15, 2026, 3:54 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
9.7
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.