Bulletin ID
Security updates available for Content Credentials SDK | APSB26-111
|
|
Date Published |
Priority |
|
APSB26-111 |
August 11, 2026 |
3 |
Summary
Adobe has released security updates for Content Credentials SDK. This update addresses critical and important vulnerabilities that could result in security feature bypass, arbitrary file system write, arbitrary file system read, application denial-of-service, and privilege escalation.
Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates.
Affected versions
| Product | Affected version | Platform |
|---|---|---|
| Content Credentials Rust SDK | c2pa-v0.90.5 and earlier | All |
| C2PA Tool | c2patool-v0.27.5 and earlier | All |
| Content Credentials JS SDK | @contentauth/c2pa-web@0.12.0 and earlier | All |
Solution
Adobe categorizes these updates with the following priority rating and recommends users update their installation to the newest version:
| Product | Updated version | Platform | Priority rating | Availability |
|---|---|---|---|---|
| Content Credentials Rust SDK |
c2pa-v0.90.6 | All | 3 | Release Notes |
| C2PA Tool |
c2patool-v0.27.6 | All | 3 | Release Notes |
| Content Credentials JS SDK |
@contentauth/c2pa-web@0.12.1 | All | 3 | Release Notes |
Vulnerability Details
| Vulnerability Category | Vulnerability Impact | Severity | CVSS base score | CVSS vector | CVE Number |
Uncontrolled Resource Consumption (CWE-400) |
Application denial-of-service |
Critical |
7.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
CVE-2026-48439 |
NULL Pointer Dereference (CWE-476) |
Application denial-of-service |
Critical |
7.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
CVE-2026-48438 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) |
Arbitrary file system write |
Critical |
7.1 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N |
CVE-2026-48442 |
Improper Input Validation (CWE-20) |
Security feature bypass |
Important |
6.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
CVE-2026-48436 |
Integer Overflow or Wraparound (CWE-190) |
Application denial-of-service |
Important |
6.2 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
CVE-2026-48387 |
Integer Underflow (Wrap or Wraparound) (CWE-191) |
Application denial-of-service |
Important |
6.2 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
CVE-2026-48435 |
Integer Overflow or Wraparound (CWE-190) |
Application denial-of-service |
Important |
6.2 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
CVE-2026-48445 |
Uncontrolled Resource Consumption (CWE-400) |
Application denial-of-service |
Important |
6.2 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
CVE-2026-48434 |
Integer Overflow or Wraparound (CWE-190) |
Application denial-of-service |
Important |
6.2 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
CVE-2026-48444 |
Uncontrolled Resource Consumption (CWE-400) |
Application denial-of-service |
Important |
6.2 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
CVE-2026-48443 |
| Integer Underflow (Wrap or Wraparound) (CWE-191) | Application denial-of-service | Important | 6.2 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | CVE-2026-71389 |
Improper Certificate Validation (CWE-295) |
Security feature bypass |
Important |
5.5 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
CVE-2026-48437 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) |
Arbitrary file system read |
Important |
5.5 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
CVE-2026-48446 |
| Server-Side Request Forgery (SSRF) (CWE-918) | Security feature bypass | Important | 4.7 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N | CVE-2026-47922 |
Improper Input Validation (CWE-20) |
Privilege escalation |
Important |
4.0 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
CVE-2026-71390 |
Acknowledgments
Adobe would like to thank the following researchers for reporting this issue and for working with Adobe to help protect our customers.
- 0x0.eth (0x0doteth) — CVE-2026-47922
- bau1u — CVE-2026-48439, CVE-2026-48438, CVE-2026-48387, CVE-2026-48435, CVE-2026-48445, CVE-2026-48434, CVE-2026-48443, CVE-2026-71389
- Sindid (sndd) — CVE-2026-48442
- susdrip (susdrip) — CVE-2026-48437
- MJ (mickeyjoe) — CVE-2026-48436
- Sneharghya (sneharghyaroy) — CVE-2026-48446
- Ashutosh (ashutosh0x) — CVE-2026-48444
- Cantina (cantina-security) — CVE-2026-71390
For more information, visit https://helpx.adobe.com/security.html, or email PSIRT@adobe.com