5.5

CVE-2026-48437

CAI Content Credentials | Improper Certificate Validation (CWE-295)

CAI Content Credentials is affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AdobeC2pa SwPlatformrust Version < 0.90.6
AdobeC2pa-web SwPlatformnode.js Version < 0.12.1
AdobeC2patool Version < 0.27.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.1% 0.011
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Adobe 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-111.html
Vendor Advisory