Path Traversal Vulnerability in CAI Content Credentials by Adobe
CVE-2026-48442

7.1HIGH

What is CVE-2026-48442?

The CAI Content Credentials product by Adobe is vulnerable to an improper limitation of a pathname, commonly referred to as a path traversal vulnerability. This security flaw allows attackers to gain unauthorized read access to files or directories that are outside the designated restrictions. Exploiting this vulnerability does not require any user interaction, making it a significant concern for users who rely on this product for secure content authentication. To mitigate risks, users are advised to monitor the security advisory provided by Adobe and apply any necessary updates or patches.

Affected Version(s)

Content Credentials Command-Line Tool 0

Content Credentials Command-Line Tool 0

Content Credentials JS SDK 0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.