Adobe Security Bulletin

Security updates available for Content Credentials SDK | APSB26-61

Bulletin ID

Date Published

Priority

APSB26-61

June 9, 2026

3

Summary

Adobe has released security updates for Content Credentials SDK. This update addresses critical and important vulnerabilities  that could result in application denial-of-service and arbitrary file system write.

Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates.  

Affected versions

Product Affected version Platform
Content Credentials JS SDK @contentauth/c2pa-web@0.7.1 and earlier Windows, macOS, Linux, iOS, Android
Content Credentials Rust SDK c2pa-v0.80.1 and earlier Windows, macOS, Linux, iOS, Android

Solution

Adobe categorizes these updates with the following priority rating and recommends users update their installation to the newest version:

Product Updated version Platform Priority rating Availability
Content Credentials JS SDK
@contentauth/c2pa-web@0.8.3 Windows, macOS, Linux, iOS, Android 3 Release Notes
Content Credentials Rust SDK c2pa-v0.85.1 Windows, macOS, Linux, iOS, Android 3 Release Notes

Vulnerability Details

Vulnerability Category Vulnerability Impact Severity CVSS base score CVSS vector CVE Number
Integer Overflow or Wraparound (CWE-190) Application denial-of-service Critical 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2026-34711
Improper Input Validation (CWE-20) Application denial-of-service Critical 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2026-34712
Uncontrolled Resource Consumption (CWE-400) Application denial-of-service Critical 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2026-34713
Uncontrolled Resource Consumption (CWE-400) Application denial-of-service Important 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2026-47902
Improper Input Validation (CWE-20) Application denial-of-service Important 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2026-47903
Uncontrolled Resource Consumption (CWE-400) Application denial-of-service Important 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2026-47904
Uncontrolled Resource Consumption (CWE-400) Application denial-of-service Important 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2026-47905
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) Arbitrary file system write Important 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N CVE-2026-34657

Acknowledgments

Adobe would like to thank the following researchers for reporting this issue and for working with Adobe to help protect our customers.        

  • bau1u - CVE-2026-34712, CVE-2026-34713, CVE-2026-47902, CVE-2026-47903, CVE-2026-47904, CVE-2026-47905
  • exploitguru101 - CVE-2026-34711
  • Amirul Akmal Bin Amiruddin (m411) - CVE-2026-34657

NOTE: Adobe has a public bug bounty program with HackerOne. If you are interested in working with Adobe as an external security researcher, please check us out here: https://hackerone.com/adobe.

 

For more information, visit https://helpx.adobe.com/security.html, or email PSIRT@adobe.com

Adobe, Inc.

Get help faster and easier

New user?