Junglewise Threat Intelligence

CVE-2026-34669: Adobe CAI Content Credentials denial of service via improper input validation

CVE-2026-34669 · Severity: medium · CVSS 6.2 · Published 2026-05-12

Technologies: Adobe C2pa, Adobe C2pa-Web, Adobe Content Credentials SDK, Adobe c2pa-v (Rust SDK). Vendors: Adobe.

Executive brief

Adobe CAI Content Credentials, a toolkit used to verify the authenticity and origin of digital media, is affected by a security flaw that can cause applications to crash. By providing specially crafted input, an attacker can trigger a denial-of-service condition, making the affected software unavailable. This impact is limited to service availability and does not involve the theft of customer data.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Adobe Content Authenticity Initiative (CAI) SDKs, specifically the c2pa-web (Node.js) and c2pa (Rust) implementations. The flaw allows a local attacker to provide malformed input that the library fails to process safely, resulting in an application crash. The attack vector is classified as local, but it does not require specific user interaction or elevated privileges to trigger the denial-of-service condition. Patches are available in c2pa-web version 0.7.1 and c2pa version 0.80.1.

Affected products

  • Adobe c2pa-web 0.7.0 and earlier
  • Adobe c2pa-v (Rust SDK) 0.78.2 and earlier

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory: Adobe published APSB26-53 advisory

References

Related threats