Junglewise Threat Intelligence

CVE-2026-47903: Adobe Content Authenticity SDK improper input validation

CVE-2026-47903 · Severity: medium · CVSS 6.2 · Published 2026-06-09

Technologies: Adobe Content Authenticity SDK (c2pa-web). Vendors: Adobe.

Executive brief

Adobe Content Credentials, a tool used to verify the origin and history of digital content, is affected by a flaw that can cause applications using it to crash. An attacker could exploit this to disrupt services or disable the authenticity verification features of a website or application. This could lead to temporary outages or the inability for users to trust the digital media they are viewing.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Adobe Content Authenticity Initiative (CAI) SDKs, specifically affecting the c2pa-web and c2pa-rust implementations. The flaw allows an attacker to provide specially crafted input that causes the application to crash, resulting in a denial-of-service (DoS). The attack vector is classified as local, but notably requires no prior authentication or user interaction to trigger the crash. Affected versions include c2pa-web at or below 0.7.1 and c2pa-rust at or below 0.80.1. Users are advised to update to the latest versions provided by Adobe to mitigate this risk.

Affected products

  • Adobe Content Authenticity SDK (c2pa-web) 0.7.1 and earlier
  • Adobe Content Authenticity SDK (c2pa-rust) 0.80.1 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats