Junglewise Threat Intelligence

CVE-2026-47902: Adobe CAI Content Credentials resource consumption in c2pa-web and c2pa-v

CVE-2026-47902 · Severity: medium · CVSS 6.2 · Published 2026-06-09

Technologies: Adobe Content Credentials (c2pa-v), Adobe Content Credentials (c2pa-web). Vendors: Adobe.

Executive brief

Adobe Content Credentials, a toolset used to verify the authenticity and origin of digital content, is affected by a flaw that allows for resource exhaustion. An attacker can exploit this to crash applications or services using the library, leading to a denial-of-service. This could disrupt workflows that rely on verifying digital media provenance without requiring any user interaction.

Technical details

An uncontrolled resource consumption vulnerability (CWE-400) exists in the Adobe Content Authenticity Initiative (CAI) Content Credentials SDK. The flaw affects the c2pa-web (v0.7.1 and earlier) and c2pa-v (v0.80.1 and earlier) components. An attacker can exploit this vulnerability to exhaust system resources, resulting in a denial-of-service (DoS) condition for the host application. The attack vector is classified as local, and exploitation does not require prior authentication or user interaction. Users are advised to review Adobe advisory APSB26-61 for patching information.

Affected products

  • Adobe Content Credentials (c2pa-web) 0.7.1 and earlier
  • Adobe Content Credentials (c2pa-v) 0.80.1 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats