Junglewise Threat Intelligence

CVE-2026-71442: Adobe CAI Content Credentials integer underflow denial-of-service

CVE-2026-71442 · Severity: high · CVSS 7.5 · Published 2026-08-25

Technologies: Adobe C2pa, Adobe C2patool. Vendors: Adobe.

Executive brief

Adobe's Content Authenticity Initiative (CAI) Content Credentials component is vulnerable to an integer underflow flaw that allows an attacker to crash the application without requiring user interaction. Exploitation of this vulnerability causes a denial-of-service condition, potentially disrupting services that rely on content credential verification and authentication.

Technical details

The vulnerability is an integer underflow (wrap or wraparound) condition in CAI Content Credentials. The flaw allows an unauthenticated, network-adjacent attacker to send a specially crafted request that triggers the underflow, causing the application to crash and enter a denial-of-service state. No user interaction is required to trigger the vulnerability. The exact vulnerable component and root cause are not publicly detailed in available sources, but the issue results in application termination rather than data compromise.

Affected products

  • Adobe Content Authenticity Initiative Content Credentials

Timeline

  • 2026-08-25: disclosed

References

Related threats