Junglewise Threat Intelligence

CVE-2026-34713: Adobe CAI Content Credentials resource exhaustion in Content Authenticity SDK

CVE-2026-34713 · Severity: high · CVSS 7.5 · Published 2026-06-09

Technologies: Adobe Content Authenticity SDK (c2pa-web). Vendors: Adobe.

Executive brief

Adobe Content Credentials (CAI) tools are used to verify the origin and history of digital media to ensure authenticity. A security flaw in these tools allows a remote attacker to overwhelm the system's resources, such as memory or processing power. This can lead to a denial-of-service, making the application or verification service unavailable to legitimate users.

Technical details

An uncontrolled resource consumption vulnerability (CWE-400) exists in the Adobe Content Authenticity SDK (specifically the c2pa-web and c2pa-rs implementations). The flaw allows a remote, unauthenticated attacker to send specially crafted requests or data that exhaust system resources. This results in a denial-of-service (DoS) condition for the affected application. The attack can be carried out over the network without any user interaction. Adobe has addressed this in APSB26-61; users should update to the latest versions of the SDK.

Affected products

  • Adobe Content Authenticity SDK (c2pa-web) 0.7.1 and earlier
  • Adobe Content Authenticity SDK (c2pa-rs) 0.80.1 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory: Adobe APSB26-61 published

References

Related threats