Junglewise Threat Intelligence

CVE-2026-76189: Adobe Content Credentials integer underflow in decoder

CVE-2026-76189 · Severity: medium · CVSS 6.2 · Published 2026-08-25

Technologies: Adobe C2pa, Adobe C2patool, Adobe Content Credentials. Vendors: Adobe.

Executive brief

Adobe Content Credentials, a component used to verify the authenticity and origin of digital content, is vulnerable to an integer underflow flaw. An attacker could craft a malicious file to crash the application without requiring any user interaction, causing a denial-of-service condition and disrupting content verification workflows.

Technical details

The vulnerability is an integer underflow (wraparound) condition in the Content Credentials decoder that processes untrusted input. The defect allows an attacker to supply specially crafted input that causes a numeric value to wrap around, resulting in memory corruption or logic errors. The flaw is reachable over the network without authentication or user interaction, allowing remote denial-of-service. Exploitation crashes the affected application. Patches are available from Adobe.

Affected products

  • Adobe Content Credentials

Timeline

  • 2026-08-25: disclosed

References

Related threats