CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Arbitrary file system read. An attacker could leverage this vulnerability to gain unauthorized read access to files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction. Scope is changed.
Metrics
Affected Vendors & Products
References
History
Fri, 14 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Adobe c2pa
Adobe c2pa-web Adobe c2patool |
|
| CPEs | cpe:2.3:a:adobe:c2pa-web:*:*:*:*:*:node.js:*:* cpe:2.3:a:adobe:c2pa:*:*:*:*:*:rust:*:* cpe:2.3:a:adobe:c2patool:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Adobe c2pa
Adobe c2pa-web Adobe c2patool |
Thu, 13 Aug 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Adobe
Adobe content Credentials Command-line Tool Adobe content Credentials Js Sdk Adobe content Credentials Rust Sdk |
|
| Vendors & Products |
Adobe
Adobe content Credentials Command-line Tool Adobe content Credentials Js Sdk Adobe content Credentials Rust Sdk |
Wed, 12 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Arbitrary file system read. An attacker could leverage this vulnerability to gain unauthorized read access to files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Title | CAI Content Credentials | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: adobe
Published: 2026-08-11T16:59:59.272Z
Updated: 2026-08-27T22:33:55.158Z
Reserved: 2026-05-21T15:28:38.146Z
Link: CVE-2026-48442
Updated: 2026-08-12T16:12:05.639Z
Status : Analyzed
Published: 2026-08-11T17:18:01.450
Modified: 2026-08-28T00:18:02.157
Link: CVE-2026-48442
No data.