Junglewise Threat Intelligence

CVE-2026-48351: Adobe Content Credentials denial of service via improper input validation

CVE-2026-48351 · Severity: high · CVSS 7.5 · Published 2026-07-14

Technologies: Adobe Content Credentials JS SDK, Adobe Content Credentials Rust SDK, Adobe Content Credentials Command-Line Tool. Vendors: Adobe.

Executive brief

Adobe Content Credentials tools, which are used to verify the authenticity and origin of digital content, are vulnerable to a flaw that can cause them to crash. An attacker can exploit this remotely to disable the verification service, preventing users from validating the history or integrity of digital media. This could disrupt workflows that rely on content authenticity and impact the availability of verification services.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Adobe Content Authenticity Initiative (CAI) SDKs and command-line tools. The flaw allows a remote, unauthenticated attacker to send specially crafted input that triggers an application crash, resulting in a denial-of-service (DoS) condition. The vulnerability affects the Rust SDK, JavaScript SDK, and the C2PA command-line tool. No user interaction is required for exploitation. Adobe has released updates to address this issue in Content Credentials Rust SDK v0.85.2, Command-Line Tool v0.26.65, and JS SDK v0.17.0.

Affected products

  • Adobe Content Credentials Rust SDK (c2pa) <= c2pa-v0.84.0
  • Adobe Content Credentials Command-Line Tool (c2patool) <= c2patool-v0.16.5
  • Adobe Content Credentials JS SDK (@contentauth/c2pa-js) <= @contentauth/c2pa-js-v0.16.0

Timeline

  • 2026-07-14: advisory: Initial disclosure by Adobe and NVD publication

References

Related threats