SB20260814111 - Multiple vulnerabilities in Adobe Content Credentials SDK
Published: August 14, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 15 vulnerabilities.
1) Improper Certificate Validation (CVE-ID: CVE-2026-48437)
CWE-ID: CWE-295 - Improper Certificate Validation
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass security features.
The vulnerability exists due to improper certificate validation in the Content Credentials SDK when validating certificates. A remote attacker can use a crafted certificate validation scenario to bypass security features.
User interaction is required.
2) Resource exhaustion (CVE-ID: CVE-2026-48443)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the Content Credentials SDK when processing input. A remote attacker can send a specially crafted input to cause a denial of service.
3) Input validation error (CVE-ID: CVE-2026-71390)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper input validation in the Content Credentials SDK when processing input. A remote attacker can provide crafted input to escalate privileges.
4) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-47922)
CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:L/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass security features.
The vulnerability exists due to server-side request forgery in the Content Credentials SDK when handling requests. A remote attacker can send a specially crafted request to bypass security features.
User interaction is required.
5) Path traversal (CVE-ID: CVE-2026-48446)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to path traversal in the Content Credentials SDK when handling file paths. A remote attacker can supply a crafted pathname to disclose sensitive information.
User interaction is required.
6) Resource exhaustion (CVE-ID: CVE-2026-48439)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the Content Credentials SDK when processing input. A remote attacker can send a specially crafted input to cause a denial of service.
7) Integer underflow (CVE-ID: CVE-2026-71389)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer underflow in the Content Credentials SDK when processing input. A remote attacker can send a specially crafted input to cause a denial of service.
8) Integer overflow (CVE-ID: CVE-2026-48444)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in the Content Credentials SDK when processing input. A remote attacker can send a specially crafted input to cause a denial of service.
9) Resource exhaustion (CVE-ID: CVE-2026-48434)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the Content Credentials SDK when processing input. A remote attacker can send a specially crafted input to cause a denial of service.
10) Integer overflow (CVE-ID: CVE-2026-48445)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in the Content Credentials SDK when processing input. A remote attacker can send a specially crafted input to cause a denial of service.
11) Integer underflow (CVE-ID: CVE-2026-48435)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer underflow in the Content Credentials SDK when processing input. A remote attacker can send a specially crafted input to cause a denial of service.
12) Integer overflow (CVE-ID: CVE-2026-48387)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in the Content Credentials SDK when processing input. A remote attacker can send a specially crafted input to cause a denial of service.
13) Input validation error (CVE-ID: CVE-2026-48436)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass security features.
The vulnerability exists due to improper input validation in the Content Credentials SDK when processing input. A remote attacker can provide crafted input to bypass security features.
User interaction is required.
14) Path traversal (CVE-ID: CVE-2026-48442)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to write arbitrary files to the file system.
The vulnerability exists due to path traversal in the Content Credentials SDK when handling file paths. A remote attacker can supply a crafted pathname to write arbitrary files to the file system.
15) NULL pointer dereference (CVE-ID: CVE-2026-48438)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to null pointer dereference in the Content Credentials SDK when processing input. A remote attacker can send a specially crafted input to cause a denial of service.
Remediation
Install update from vendor's website.