Junglewise Threat Intelligence

CVE-2026-47904: Adobe Content Credentials uncontrolled resource consumption

CVE-2026-47904 · Severity: medium · CVSS 6.2 · Published 2026-06-09

Technologies: Adobe Content Credentials (c2pa-v), Adobe Content Credentials (c2pa-web). Vendors: Adobe.

Executive brief

Adobe Content Credentials, a tool used to verify the authenticity and origin of digital content, is affected by a flaw that allows for resource exhaustion. An attacker can exploit this to crash the application or make it unresponsive, leading to a denial-of-service. This impact prevents users from verifying the provenance of media, potentially disrupting workflows that rely on content authenticity.

Technical details

An uncontrolled resource consumption vulnerability (CWE-400) exists in the Adobe Content Authenticity Initiative (CAI) SDK. The flaw affects the c2pa-web and c2pa-v libraries, where improper handling of incoming data can lead to system resource exhaustion. The attack vector is classified as local, and exploitation does not require administrative privileges or user interaction. Successful exploitation results in a denial-of-service (DoS) condition for the affected application. Users are advised to update to the latest versions of the Content Authenticity SDK as referenced in Adobe security bulletin APSB26-61.

Affected products

  • Adobe Content Credentials (c2pa-web) 0.7.1 and earlier
  • Adobe Content Credentials (c2pa-v) 0.80.1 and earlier

Timeline

  • 2026-06-09: advisory: Adobe published security bulletin APSB26-61
  • 2026-06-09: disclosed: CVE-2026-47904 published to NVD

References

Related threats