Junglewise Threat Intelligence

CVE-2026-34657: Adobe Content Credentials path traversal in Content Authenticity SDK

CVE-2026-34657 · Severity: medium · CVSS 5.5 · Published 2026-06-09

Technologies: Adobe Content Authenticity SDK (c2pa-web). Vendors: Adobe.

Executive brief

Adobe Content Credentials, a tool used to verify the origin and history of digital media, contains a security flaw that could allow an attacker to write files to unauthorized locations on a user's computer. To exploit this, an attacker would need to trick a user into extracting a specially crafted malicious file. This could lead to the corruption of system files or the placement of unauthorized data on the victim's machine.

Technical details

A path traversal vulnerability (CWE-22) exists in the Adobe Content Authenticity SDK (specifically c2pa-web and c2pa-rs components). The flaw stems from improper limitation of pathnames during file extraction processes. An attacker can exploit this by providing a maliciously crafted file that, when extracted by a victim, writes data to unauthorized directories outside of the intended destination. This is a local attack requiring user interaction (UI:R) and can result in a high impact on system integrity (I:H) by overwriting or creating arbitrary files.

Affected products

  • Adobe Content Authenticity SDK (c2pa-web) 0.7.1 and earlier
  • Adobe Content Authenticity SDK (c2pa-rs) 0.80.1 and earlier

Timeline

  • 2026-06-09: disclosed: Initial disclosure by Adobe
  • 2026-06-09: advisory: NVD publication date

References

Related threats