Executive brief
Adobe's CAI Content Credentials is a security tool that manages and verifies the authenticity of digital content. An improper input validation flaw allows attackers to bypass security controls and gain unauthorized write access without requiring user interaction. This could enable attackers to forge or tamper with authenticated content credentials.
Technical details
The vulnerability is a CWE-20 improper input validation flaw in CAI Content Credentials that permits bypass of the product's security features. An attacker with network access can exploit this to gain unauthorized write access; no user interaction or prior authentication is required. A fix is expected from the vendor (Adobe APSB26-147).
Affected products
- Adobe CAI Content Credentials
Timeline
- 2026-09-22: disclosed