Junglewise Threat Intelligence

CVE-2026-34668: Adobe CAI Content Credentials denial of service via improper input validation

CVE-2026-34668 · Severity: medium · CVSS 6.2 · Published 2026-05-12

Technologies: Adobe C2pa, Adobe C2pa-Web, Adobe Content Credentials SDK, Adobe c2pa-v (Rust SDK). Vendors: Adobe.

Executive brief

Adobe CAI Content Credentials, a toolset used to verify the authenticity and origin of digital content, is affected by a security flaw that can cause applications to crash. An attacker could exploit this vulnerability to disrupt services and cause a denial-of-service condition. This impact is limited to system availability and does not involve the theft of customer data.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Adobe Content Authenticity Initiative (CAI) SDKs, specifically the c2pa-web (Node.js) and c2pa-v (Rust) implementations. The flaw allows an attacker to provide specially crafted input that the application fails to validate correctly, resulting in a crash. The attack vector is classified as local, meaning the attacker typically needs the ability to submit data to the affected library on the host system. No user interaction is required for exploitation. The vulnerability has been addressed in c2pa-web version 0.7.1 and c2pa-v version 0.80.1.

Affected products

  • Adobe c2pa-web <= 0.7.0
  • Adobe c2pa-v (Rust SDK) <= 0.78.2

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats