Junglewise Threat Intelligence

CVE-2026-71360: Adobe CAI Content Credentials uncontrolled resource consumption

CVE-2026-71360 · Severity: high · CVSS 7.5 · Published 2026-08-25

Technologies: Adobe C2pa, Adobe C2patool, Adobe Content Credentials. Vendors: Adobe.

Executive brief

Adobe's Content Authenticity Initiative (CAI) Content Credentials component is vulnerable to a resource exhaustion attack that can crash the application. An attacker can trigger this vulnerability remotely without requiring user interaction, potentially disrupting services that rely on content authentication and credential verification.

Technical details

The vulnerability is an uncontrolled resource consumption issue (CWE-400) in the CAI Content Credentials component. The vulnerability allows an attacker to exhaust system resources such as memory or CPU by sending crafted requests, leading to a denial-of-service condition. The attack is network-reachable and requires no user interaction or prior authentication. Exploitation results in application unavailability. A patch should be available from Adobe's security advisory APSB26-110.

Affected products

  • Adobe Content Credentials

Timeline

  • 2026-08-25: disclosed

References

Related threats