SB20260814111 - Multiple vulnerabilities in Adobe Content Credentials SDK



SB20260814111 - Multiple vulnerabilities in Adobe Content Credentials SDK

Published: August 14, 2026

Security Bulletin ID SB20260814111
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 15
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 40% Low 60%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 15 vulnerabilities.


1) Improper Certificate Validation (CVE-ID: CVE-2026-48437)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass security features.

The vulnerability exists due to improper certificate validation in the Content Credentials SDK when validating certificates. A remote attacker can use a crafted certificate validation scenario to bypass security features.

User interaction is required.


2) Resource exhaustion (CVE-ID: CVE-2026-48443)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in the Content Credentials SDK when processing input. A remote attacker can send a specially crafted input to cause a denial of service.


3) Input validation error (CVE-ID: CVE-2026-71390)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper input validation in the Content Credentials SDK when processing input. A remote attacker can provide crafted input to escalate privileges.


4) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-47922)

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:L/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass security features.

The vulnerability exists due to server-side request forgery in the Content Credentials SDK when handling requests. A remote attacker can send a specially crafted request to bypass security features.

User interaction is required.


5) Path traversal (CVE-ID: CVE-2026-48446)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to path traversal in the Content Credentials SDK when handling file paths. A remote attacker can supply a crafted pathname to disclose sensitive information.

User interaction is required.


6) Resource exhaustion (CVE-ID: CVE-2026-48439)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in the Content Credentials SDK when processing input. A remote attacker can send a specially crafted input to cause a denial of service.


7) Integer underflow (CVE-ID: CVE-2026-71389)

CWE-ID: CWE-191 - Integer underflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to integer underflow in the Content Credentials SDK when processing input. A remote attacker can send a specially crafted input to cause a denial of service.


8) Integer overflow (CVE-ID: CVE-2026-48444)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to integer overflow in the Content Credentials SDK when processing input. A remote attacker can send a specially crafted input to cause a denial of service.


9) Resource exhaustion (CVE-ID: CVE-2026-48434)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in the Content Credentials SDK when processing input. A remote attacker can send a specially crafted input to cause a denial of service.


10) Integer overflow (CVE-ID: CVE-2026-48445)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to integer overflow in the Content Credentials SDK when processing input. A remote attacker can send a specially crafted input to cause a denial of service.


11) Integer underflow (CVE-ID: CVE-2026-48435)

CWE-ID: CWE-191 - Integer underflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to integer underflow in the Content Credentials SDK when processing input. A remote attacker can send a specially crafted input to cause a denial of service.


12) Integer overflow (CVE-ID: CVE-2026-48387)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to integer overflow in the Content Credentials SDK when processing input. A remote attacker can send a specially crafted input to cause a denial of service.


13) Input validation error (CVE-ID: CVE-2026-48436)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass security features.

The vulnerability exists due to improper input validation in the Content Credentials SDK when processing input. A remote attacker can provide crafted input to bypass security features.

User interaction is required.


14) Path traversal (CVE-ID: CVE-2026-48442)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to write arbitrary files to the file system.

The vulnerability exists due to path traversal in the Content Credentials SDK when handling file paths. A remote attacker can supply a crafted pathname to write arbitrary files to the file system.


15) NULL pointer dereference (CVE-ID: CVE-2026-48438)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to null pointer dereference in the Content Credentials SDK when processing input. A remote attacker can send a specially crafted input to cause a denial of service.


Remediation

Install update from vendor's website.