CVE-2026-75638
6.5Adobe · Content Credentials Rust SDK
Adobe Content Credentials Rust SDK and Command-Line Tool are vulnerable to improper input validation, allowing an attacker to bypass security features and gain unauthorized write access.
Executive summary
Adobe Content Credentials Rust SDK and Command-Line Tool are susceptible to a security feature bypass vulnerability that could allow unauthorized write operations through user interaction.
Vulnerability
This vulnerability, categorized as CWE-20: Improper Input Validation, allows for security feature bypass. The flaw is triggered when an unauthenticated attacker successfully lures a user into interacting with a malicious URL or compromised web page.
Business impact
The ability for an unauthorized party to gain write access to Content Credentials poses a significant risk to data integrity and the authenticity of digital assets. While the CVSS score of 6.5 reflects a medium severity, the potential for unauthorized modification of security-sensitive metadata can lead to long-term reputational damage and the compromise of supply chain trust. Organizations relying on these tools for content verification must prioritize remediation to prevent the unauthorized alteration of protected files.
Remediation
Immediate Action: Update Adobe Content Credentials Rust SDK to version c2pa-v0.90.17 or later and the Command-Line Tool to version c2patool-v0.27.17 or later.
Proactive Monitoring: Monitor system access logs for anomalous file write operations or unexpected calls to the Content Credentials utility.
Compensating Controls: Implement strict content security policies and user awareness training to mitigate the risk of users interacting with untrusted or malicious URLs.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability presents a clear risk to data integrity within the Adobe Content Credentials ecosystem. Administrators should verify their current versions immediately and apply the provided updates to the Rust SDK and Command-Line Tool as soon as possible. Given the reliance on user interaction, coupling these updates with organizational security awareness training is highly recommended to ensure comprehensive protection against exploitation.
More Adobe CVEs all →
History
- Analyst report written