Integer Underflow Vulnerability in CAI Content Credentials by Adobe
CVE-2026-76189

6.2MEDIUM

Key Information:

Vendor

Adobe

Vendor
CVE Published:
25 August 2026

What is CVE-2026-76189?

The CAI Content Credentials from Adobe is susceptible to an Integer Underflow vulnerability that can lead to application instability. This vulnerability allows an attacker to exploit the underlying conditions to trigger a crash in the application, consequently resulting in a denial-of-service situation. Notably, no user interaction is required for an attacker to exploit this vulnerability, making it a concerning issue for users of the affected product.

Affected Version(s)

C2PA Tool 0

Content Credentials Rust SDK 0

C2PA Tool c2patool-v0.27.11

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.