Junglewise Threat Intelligence

CVE-2026-76198: Adobe CAI Content Credentials improper input validation in file read

CVE-2026-76198 · Severity: medium · CVSS 5.5 · Published 2026-08-25

Technologies: Adobe C2pa, Adobe C2patool. Vendors: Adobe.

Executive brief

Adobe's Content Authenticity Initiative (CAI) SDK is a tool used by developers to embed and verify authenticity credentials in digital media and documents. A flaw in how the software validates user input could allow an attacker to read arbitrary files from a victim's system, exposing sensitive information. Exploitation requires a victim to open a specially crafted malicious file.

Technical details

The vulnerability is an improper input validation flaw in the CAI Content Credentials component that fails to adequately sanitize file path parameters, allowing path traversal attacks. An attacker can craft a malicious file that, when opened by a victim using an application incorporating the vulnerable SDK, bypasses access restrictions to read files and directories outside the intended scope. The attack requires user interaction (opening a malicious file) but can result in unauthorized access to sensitive data on the victim's system. Adobe published a security update to address this issue.

Affected products

  • Adobe CAI Content Credentials

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: advisory

References

Related threats