.

Adobe Security Bulletin

Last updated on Aug 11, 2026

Security updates available for Content Credentials SDK | APSB26-111

Bulletin ID
Date published
Priority
APSB26-111
August 11, 2026
3

Summary

Adobe has released security updates for Content Credentials SDK. This update addresses critical and important vulnerabilities that could result in security feature bypass, arbitrary file system write, arbitrary file system read, application denial-of-service, and privilege escalation.

Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates.

Affected versions

Product
Affected version
Platform
Content Credentials Rust SDK
c2pa-v0.90.5 and earlier
All
C2PA Tool
c2patool-v0.27.5 and earlier
All
Content Credentials JS SDK
@contentauth/c2pa-web@0.12.0 and earlier
All

Solution

Adobe categorizes these updates with the following priority rating and recommends users update their installation to the newest version:

Product
Updated version
Platform
Priority rating
Availability
Content Credentials Rust SDK
c2pa-v0.90.6
All
3
C2PA Tool
c2patool-v0.27.6
All
3
Content Credentials JS SDK
@contentauth/c2pa-web@0.12.1
All
3

Vulnerability Details

Vulnerability category
Vulnerability impact
Severity
CVSS base score
CVSS vector
CVE number
Uncontrolled Resource Consumption (CWE-400)
Application denial-of-service
Critical
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVE-2026-48439
NULL Pointer Dereference (CWE-476)
Application denial-of-service
Critical
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVE-2026-48438
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Arbitrary file system write
Critical
7.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
CVE-2026-48442
Improper Input Validation (CWE-20)
Security feature bypass
Important
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVE-2026-48436
Integer Overflow or Wraparound (CWE-190)
Application denial-of-service
Important
6.2
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVE-2026-48387
Integer Underflow (Wrap or Wraparound) (CWE-191)
Application denial-of-service
Important
6.2
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVE-2026-48435
Integer Overflow or Wraparound (CWE-190)
Application denial-of-service
Important
6.2
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVE-2026-48445
Uncontrolled Resource Consumption (CWE-400)
Application denial-of-service
Important
6.2
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVE-2026-48434
Integer Overflow or Wraparound (CWE-190)
Application denial-of-service
Important
6.2
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVE-2026-48444
Uncontrolled Resource Consumption (CWE-400)
Application denial-of-service
Important
6.2
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVE-2026-48443
Integer Underflow (Wrap or Wraparound) (CWE-191)
Application denial-of-service
Important
6.2
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVE-2026-71389
Improper Certificate Validation (CWE-295)
Security feature bypass
Important
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVE-2026-48437
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Arbitrary file system read
Important
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVE-2026-48446
Server-Side Request Forgery (SSRF) (CWE-918)
Security feature bypass
Important
4.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
CVE-2026-47922
Improper Input Validation (CWE-20)
Privilege escalation
Important
4.0
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVE-2026-71390

Acknowledgments

Adobe would like to thank the following researchers for reporting this issue and for working with Adobe to help protect our customers.

  • 0x0.eth (0x0doteth) — CVE-2026-47922
  • bau1u — CVE-2026-48439, CVE-2026-48438, CVE-2026-48387, CVE-2026-48435, CVE-2026-48445, CVE-2026-48434, CVE-2026-48443, CVE-2026-71389
  • Sindid (sndd) — CVE-2026-48442
  • susdrip (susdrip) — CVE-2026-48437
  • MJ (mickeyjoe) — CVE-2026-48436
  • Sneharghya (sneharghyaroy) — CVE-2026-48446
  • Ashutosh (ashutosh0x) — CVE-2026-48444
  • Cantina (cantina-security) — CVE-2026-71390