Junglewise Threat Intelligence

CVE-2026-34680: Adobe CAI Content Credentials integer overflow denial of service

CVE-2026-34680 · Severity: medium · CVSS 6.2 · Published 2026-05-12

Technologies: Adobe C2pa, Adobe C2pa-Web, Adobe c2pa (Rust SDK), Adobe Content Credentials SDK. Vendors: Adobe.

Executive brief

Adobe CAI Content Credentials, a toolset used to verify the authenticity and origin of digital content, is affected by a software flaw that can cause applications to crash. An attacker could use this vulnerability to trigger a denial-of-service, making the content verification features unavailable. This could disrupt workflows that rely on validating the integrity of digital media.

Technical details

An integer overflow or wraparound vulnerability (CWE-190) exists in the Adobe Content Authenticity Initiative (CAI) SDKs, specifically affecting the c2pa-web (Node.js) and c2pa (Rust) implementations. The flaw occurs during the processing of content credentials, where improper arithmetic handling can lead to an application crash. The attack vector is classified as local, and exploitation does not require user interaction or specific privileges. Successful exploitation results in a denial-of-service (DoS) condition for the host application. Adobe has addressed this in c2pa-web version 0.7.1 and c2pa version 0.80.1.

Affected products

  • Adobe c2pa-web 0.7.0 and earlier
  • Adobe c2pa (Rust SDK) 0.78.2 and earlier

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats