Adobe C2pa Web: Batch of 15 Vulnerabilities in CAI Content Credentials Disclosed
Adobe C2pa Web: 15 vulnerabilities in CAI Content Credentials disclosed, including DoS, path traversal, and security bypasses.

Key findings
- 15 vulnerabilities disclosed on August 11, 2026, for Adobe C2pa Web's CAI Content Credentials component.
- Vulnerabilities include denial-of-service, path traversal, security feature bypass, and SSRF.
- Several DoS vulnerabilities stem from integer overflows/underflows and resource consumption.
- Path traversal flaws allow for arbitrary file system reads.
- Security feature bypasses could lead to unauthorized write access.
- Exploitation varies from no user interaction to requiring user interaction with malicious links.
On August 11, 2026, a batch of 15 vulnerabilities was disclosed for Adobe Inc.'s C2pa Web product, specifically within the CAI Content Credentials component. These vulnerabilities, disclosed on the same day, span a range of severity from Medium to High, with the most critical issues posing risks of denial-of-service and arbitrary file system reads. The cluster of vulnerabilities highlights potential weaknesses in input validation, resource management, and path handling within the C2pa Web product.
Several vulnerabilities fall into the category of denial-of-service (DoS) due to integer overflows, underflows, or uncontrolled resource consumption. CVE-2026-71389, CVE-2026-48445, CVE-2026-48444, CVE-2026-48435, and CVE-2026-48387 all relate to integer overflow or underflow issues that can lead to application crashes. Additionally, CVE-2026-48443 and CVE-2026-48434 involve uncontrolled resource consumption, which can also result in a DoS condition. CVE-2026-48438 specifically points to a NULL pointer dereference vulnerability, another common cause of application crashes and DoS.
Path traversal vulnerabilities, allowing for arbitrary file system reads, are also present. CVE-2026-48446 and CVE-2026-48442 both describe Improper Limitation of a Pathname to a Restricted Directory, enabling attackers to access sensitive files outside their intended scope.
Security feature bypasses are another theme within this batch. CVE-2026-71390 and CVE-2026-48436 are improper input validation vulnerabilities that could allow an attacker to bypass security measures and gain unauthorized write access. CVE-2026-48437, an improper certificate validation vulnerability, also presents a security feature bypass risk, potentially granting unauthorized write access.
Furthermore, a Server-Side Request Forgery (SSRF) vulnerability, CVE-2026-47922, was disclosed, which could lead to privilege escalation. Exploitation of this particular vulnerability requires user interaction, such as visiting a malicious URL.
The majority of these vulnerabilities, including those related to denial-of-service and security feature bypasses, do not require user interaction for exploitation. However, the SSRF and some path traversal and security bypass vulnerabilities may necessitate user interaction, such as visiting a malicious link or interacting with a compromised webpage. The disclosed vulnerabilities affect the CAI Content Credentials component of C2pa Web. Specific version information and patch details were not provided in the disclosure, but users are advised to consult Adobe's official security advisories for the latest information and remediation steps.
This coordinated disclosure of 15 vulnerabilities underscores the importance of timely patching and security updates for Adobe C2pa Web users. The breadth of issues, from denial-of-service to file system access and security bypasses, highlights the need for a comprehensive security review of the CAI Content Credentials component. Users should prioritize applying any available updates to mitigate these risks.
The vulnerabilities disclosed are: CVE-2026-71390, CVE-2026-71389, CVE-2026-48446, CVE-2026-48445, CVE-2026-48444, CVE-2026-48443, CVE-2026-48442, CVE-2026-48439, CVE-2026-48438, CVE-2026-48437, CVE-2026-48436, CVE-2026-48435, CVE-2026-48434, CVE-2026-48387, CVE-2026-47922.