CVE-2026-48287 Details
Description
CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
A vulnerability allowing arbitrary code execution has been identified in CAI Content Credentials, specifically in the Content Credentials Rust SDK, Command-Line Tool, and JS SDK, all prior to the latest versions. This issue arises from an untrusted search path vulnerability, where the execution of code can occur in the context of the current user. Exploitation of this vulnerability requires user interaction, such as visiting a maliciously crafted URL or engaging with a compromised web page.
Users are advised to update to the latest versions of the affected SDKs. The updated version for the Content Credentials Rust SDK is c2pa-v0.85.2, for the Command-Line Tool is c2patool-v0.26.65, and for the JS SDK is @contentauth/[email protected].
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-80.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-426 | Untrusted Search Path | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| adobe c2pa | <= 0.84.0 |
CPE
Remediation
| |
| adobe c2pa-web | <= 0.7.0 |
CPE
Remediation
| |
| adobe c2patool | <= 0.17.0 |
CPE
Remediation
| |
| apple iphone os | All versions |
CPE
Remediation
| |
| apple macos | All versions |
CPE
Remediation
| |
| google android | All versions |
CPE
Remediation
| |
| linux linux kernel | All versions |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 28, 2026 | CVE Modified | [email protected] |
| Jul 16, 2026 | Reanalysis | [email protected] |
| Jul 16, 2026 | Initial Analysis | [email protected] |
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | New CVE Received | [email protected] |