Executive brief
Adobe's Content Authenticity Initiative (CAI) Content Credentials is a system for verifying the integrity and origin of digital content. A validation flaw allows attackers to bypass security checks and gain unauthorized write access to content credentials by tricking users into visiting a malicious webpage or clicking a crafted link. This could enable tampering with content authenticity records and impersonating legitimate content sources.
Technical details
The vulnerability is an improper input validation flaw that permits a security feature bypass in CAI Content Credentials. Exploitation requires user interaction (visiting a malicious URL or compromised web page), allowing an attacker to gain unauthorized write access to credentials. The attack vector is network-based with user interaction as a precondition.
Affected products
- Adobe Content Authenticity Initiative (CAI) Content Credentials
Timeline
- 2026-09-22: disclosed