High severity7.1NVD Advisory· Published Aug 11, 2026· Updated Aug 28, 2026
CVE-2026-48442
CVE-2026-48442
Description
CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Arbitrary file system read. An attacker could leverage this vulnerability to gain unauthorized read access to files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction. Scope is changed.
Affected products
4cpe:2.3:a:adobe:c2pa:*:*:*:*:*:rust:*:*+ 1 more
- cpe:2.3:a:adobe:c2pa:*:*:*:*:*:rust:*:*range: <0.90.6
- cpe:2.3:a:adobe:c2pa-web:*:*:*:*:*:node.js:*:*range: <0.12.1
Patches
Vulnerability mechanics
References
1News mentions
2- Adobe C2pa Web: 15 Vulnerabilities in CAI Content Credentials Disclosed TogetherVypr Intelligence · Aug 11, 2026
- Adobe C2pa Web: Batch of 15 Vulnerabilities in CAI Content Credentials DisclosedVypr Intelligence · Aug 11, 2026