Adobe Content Credentials Improper Input Validation Vulnerability Allowing Security Feature Bypass

Vulnerability

A vulnerability in CAI Content Credentials has been identified, stemming from improper input validation. This issue could lead to a security feature bypass, allowing an attacker to gain unauthorized write access. Notably, exploitation of this vulnerability does not require any user interaction. The affected products include the Content Credentials Rust SDK, Command-Line Tool, and JS SDK, all of which are vulnerable in versions prior to the latest release.

Impact

Exploitation of this vulnerability could result in unauthorized write access, allowing attackers to bypass security measures and potentially manipulate content or data.

Remediation

Users are advised to update to the latest versions of the affected SDKs. The updated versions are: Content Credentials Rust SDK (c2pa-v0.85.2), Content Credentials Command-Line Tool (c2patool-v0.26.65), and Content Credentials JS SDK (@contentauth/c2pa-web@0.9.0).

Added: Jul 15, 2026, 3:51 AM
Updated: Jul 15, 2026, 3:51 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.7
remediation
0.0
relevance
9.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.