Adobe Security Bulletin

Security updates available for Content Credentials SDK | APSB26-111

Bulletin ID

Date Published

Priority

APSB26-111

August 11, 2026

3

Summary

Adobe has released security updates for Content Credentials SDK. This update addresses critical and important vulnerabilities  that could result in security feature bypass, arbitrary file system write, arbitrary file system read, application denial-of-service, and privilege escalation. 

Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates.  

Affected versions

Product Affected version Platform
Content Credentials Rust SDK c2pa-v0.90.5 and earlier All
C2PA Tool c2patool-v0.27.5 and earlier All
Content Credentials JS SDK @contentauth/c2pa-web@0.12.0 and earlier All

Solution

Adobe categorizes these updates with the following priority rating and recommends users update their installation to the newest version:

Product Updated version Platform Priority rating Availability
Content Credentials Rust SDK
c2pa-v0.90.6 All 3 Release Notes
C2PA Tool
c2patool-v0.27.6 All 3 Release Notes
Content Credentials JS SDK
@contentauth/c2pa-web@0.12.1 All 3 Release Notes

Vulnerability Details

Vulnerability Category Vulnerability Impact Severity CVSS base score CVSS vector CVE Number

Uncontrolled Resource Consumption (CWE-400)

Application denial-of-service

Critical

7.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2026-48439

NULL Pointer Dereference (CWE-476)

Application denial-of-service

Critical

7.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2026-48438

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)

Arbitrary file system write

Critical

7.1

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

CVE-2026-48442

Improper Input Validation (CWE-20)

Security feature bypass

Important

6.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

CVE-2026-48436

Integer Overflow or Wraparound (CWE-190)

Application denial-of-service

Important

6.2

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2026-48387

Integer Underflow (Wrap or Wraparound) (CWE-191)

Application denial-of-service

Important

6.2

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2026-48435

Integer Overflow or Wraparound (CWE-190)

Application denial-of-service

Important

6.2

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2026-48445

Uncontrolled Resource Consumption (CWE-400)

Application denial-of-service

Important

6.2

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2026-48434

Integer Overflow or Wraparound (CWE-190)

Application denial-of-service

Important

6.2

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2026-48444

Uncontrolled Resource Consumption (CWE-400)

Application denial-of-service

Important

6.2

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2026-48443

Integer Underflow (Wrap or Wraparound) (CWE-191) Application denial-of-service Important 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2026-71389

Improper Certificate Validation (CWE-295)

Security feature bypass

Important

5.5

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

CVE-2026-48437

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)

Arbitrary file system read

Important

5.5

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CVE-2026-48446

Server-Side Request Forgery (SSRF) (CWE-918) Security feature bypass Important 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N CVE-2026-47922

Improper Input Validation (CWE-20)

Privilege escalation

Important

4.0

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CVE-2026-71390
Note
Effective August 11, 2026, Adobe may assign a single CVE identifier to internally discovered vulnerabilities with the same severity rating and CWE category when a release includes systemic fixes.

Acknowledgments

Adobe would like to thank the following researchers for reporting this issue and for working with Adobe to help protect our customers.        

  • 0x0.eth (0x0doteth) — CVE-2026-47922
  • bau1u — CVE-2026-48439, CVE-2026-48438, CVE-2026-48387, CVE-2026-48435, CVE-2026-48445, CVE-2026-48434, CVE-2026-48443, CVE-2026-71389
  • Sindid (sndd) — CVE-2026-48442
  • susdrip (susdrip) — CVE-2026-48437
  • MJ (mickeyjoe) — CVE-2026-48436
  • Sneharghya (sneharghyaroy) — CVE-2026-48446
  • Ashutosh (ashutosh0x) — CVE-2026-48444
  • Cantina (cantina-security) — CVE-2026-71390

For more information, visit https://helpx.adobe.com/security.html, or email PSIRT@adobe.com

Adobe, Inc.

Get help faster and easier

New user?