Executive brief
Adobe's CAI Content Credentials component, which manages digital authenticity and provenance metadata for media files, contains a resource exhaustion vulnerability that can crash the application. An attacker can remotely trigger excessive resource consumption without requiring any user interaction, leading to service disruption.
Technical details
The vulnerability is an uncontrolled resource consumption flaw in CAI Content Credentials that permits remote denial-of-service via resource exhaustion. The attack requires only network access with no authentication or user interaction needed. Successful exploitation exhausts system resources and crashes the application.
Affected products
- Adobe CAI Content Credentials
Timeline
- 2026-09-22: disclosed
- 2026-09-22: advisory