Improper Certificate Validation Vulnerability in CAI Content Credentials by Adobe
CVE-2026-48437

5.5MEDIUM

What is CVE-2026-48437?

The CAI Content Credentials product from Adobe is susceptible to an Improper Certificate Validation vulnerability that may allow an attacker to bypass crucial security features. By exploiting this flaw, a malicious actor could gain unauthorized write access to the system. The exploitation process necessitates that the victim either visits a specifically crafted malicious URL or interacts with a compromised webpage, thus providing the attacker with the opportunity to execute their attack.

Affected Version(s)

Content Credentials Command-Line Tool 0

Content Credentials Command-Line Tool 0

Content Credentials JS SDK 0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.