Improper Input Validation in CAI Content Credentials by Adobe
CVE-2026-76198

5.5MEDIUM

Key Information:

Vendor

Adobe

Vendor
CVE Published:
25 August 2026

What is CVE-2026-76198?

The CAI Content Credentials by Adobe suffers from an Improper Input Validation vulnerability, which can be exploited to read sensitive files from the file system. This exposure occurs when an attacker tricks a victim into opening a malicious file, allowing unauthorized access to directories and sensitive information outside intended scopes. To mitigate this risk, ensure users are educated about the dangers of opening unknown files and regularly update the software for patch deployments.

Affected Version(s)

C2PA Tool 0

Content Credentials Rust SDK 0

C2PA Tool c2patool-v0.27.11

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.