Junglewise Threat Intelligence

CVE-2026-34711: Adobe CAI Content Credentials integer overflow in c2pa-web and c2pa-v

CVE-2026-34711 · Severity: high · CVSS 7.5 · Published 2026-06-09

Technologies: Adobe C2pa-Web, Adobe C2pa-Rust. Vendors: Adobe.

Executive brief

Adobe's Content Authenticity Initiative (CAI) SDK, which is used to verify the origin and history of digital media, contains a security flaw. An attacker can exploit this vulnerability to remotely crash applications that use this toolkit, potentially disrupting services that rely on content verification. This attack can be carried out over the network without any action from a legitimate user.

Technical details

An integer overflow or wraparound vulnerability (CWE-190) exists in the Adobe Content Authenticity Initiative (CAI) SDK, specifically affecting the c2pa-web and c2pa-v (Rust) implementations. The flaw allows a remote, unauthenticated attacker to trigger an application crash by providing specially crafted input that causes an integer calculation to overflow. This results in a denial-of-service (DoS) condition. The vulnerability is reachable over the network and does not require user interaction. Users are advised to update to the latest versions of the SDK as outlined in Adobe advisory APSB26-61.

Affected products

  • Adobe c2pa-web 0.7.1 and earlier
  • Adobe c2pa-rust (c2pa-v) 0.80.1 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats