Junglewise Threat Intelligence

CVE-2026-48353: Adobe Content Credentials improper input validation arbitrary file read

CVE-2026-48353 · Severity: medium · CVSS 5.5 · Published 2026-07-14

Technologies: Adobe Content Credentials JS SDK, Adobe Content Credentials Rust SDK, Adobe Content Credentials Command-Line Tool. Vendors: Adobe.

Executive brief

Adobe Content Credentials tools, which are used to verify the authenticity and origin of digital media, are affected by a security flaw that could allow unauthorized access to local files. If a user is tricked into opening a specially crafted malicious file using these tools, an attacker could read sensitive information from the user's computer. This could lead to the exposure of private data or system configuration files.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Adobe Content Authenticity (CAI) SDKs and command-line tools. The flaw allows for an arbitrary file system read when the application processes a maliciously crafted file. The attack vector is local and requires user interaction, specifically that a victim opens the malicious file using an affected version of the Rust SDK, JS SDK, or the c2patool. Successful exploitation allows an attacker to read sensitive files and directories outside the intended scope of the application. Adobe has released updates to address this issue in Rust SDK v0.85.2, CLI tool v0.26.65, and JS SDK v0.16.6.

Affected products

  • Adobe Content Credentials Rust SDK (c2pa) <= c2pa-v0.84.0
  • Adobe Content Credentials Command-Line Tool (c2patool) <= c2patool-v0.16.5
  • Adobe Content Credentials JS SDK (@contentauth/c2pa-js) <= 0.16.5

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats