7.5

CVE-2026-48295

CAI Content Credentials | Insufficiently Protected Credentials (CWE-522)

CAI Content Credentials is affected by an Insufficiently Protected Credentials vulnerability that could result in disclosure of sensitive information. An attacker could leverage this vulnerability to gain unauthorized read access. Exploitation of this issue does not require user interaction.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AdobeC2pa SwPlatformrust Version <= 0.84.0
   AppleiPhone OS Version-
   ApplemacOS Version-
   GoogleAndroid Version-
   LinuxLinux Kernel Version-
   MicrosoftWindows Version-
AdobeC2pa-web SwPlatformnode.js Version <= 0.7.0
   AppleiPhone OS Version-
   ApplemacOS Version-
   GoogleAndroid Version-
   LinuxLinux Kernel Version-
   MicrosoftWindows Version-
AdobeC2patool Version <= 0.17.0
   AppleiPhone OS Version-
   ApplemacOS Version-
   GoogleAndroid Version-
   LinuxLinux Kernel Version-
   MicrosoftWindows Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.311
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Adobe 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-80.html
Vendor Advisory