CVE-2026-71390 PUBLISHED

CAI Content Credentials | Improper Input Validation (CWE-20)

Assigner: adobe
Reserved: 06.08.2026 Published: 11.08.2026 Updated: 11.08.2026

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue does not require user interaction.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS Score: 4

Product Status

Vendor Adobe
Product Content Credentials Rust SDK
Versions Default: affected
  • affected from 0 to c2pa-v0.90.5 (incl.)
  • Version c2pa-v0.90.6 is unaffected
Vendor Adobe
Product Content Credentials Command-Line Tool
Versions Default: affected
  • affected from 0 to c2patool-v0.27.5 (incl.)
  • Version c2patool-v0.27.6 is unaffected
Vendor Adobe
Product Content Credentials JS SDK
Versions Default: affected
  • affected from 0 to @contentauth/c2pa-web@0.12.0 (incl.)
  • Version @contentauth/c2pa-web@0.12.1 is unaffected

References

Problem Types

  • Improper Input Validation (CWE-20) CWE