CAI Content Credentials | Improper Certificate Validation (CWE-295)
Published Aug 11, 2026
5.5
MEDIUMCVSS 3.1
EPSS 0.15%
Description
CAI Content Credentials is affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.
Affected products
-
Affected
- ≥ 0, ≤ c2patool-v0.27.5
Unaffected
- c2patool-v0.27.6
-
Affected
- ≥ 0, ≤ @contentauth/c2pa-web@0.12.0
Unaffected
- @contentauth/c2pa-web@0.12.1
-
Affected
- ≥ 0, ≤ c2pa-v0.90.5
Unaffected
- c2pa-v0.90.6
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Adobe | Content Credentials Command-Line Tool | unaffected | Affected
Unaffected
|
| Adobe | Content Credentials JS SDK | unaffected | Affected
Unaffected
|
| Adobe | Content Credentials Rust SDK | unaffected | Affected
Unaffected
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-56559 Advisory
- https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-111.html vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-56559 | Advisory | |
| https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-111.html | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data