SB2026082661 - Multiple vulnerabilities in Adobe Content Credentials



SB2026082661 - Multiple vulnerabilities in Adobe Content Credentials

Published: August 26, 2026

Security Bulletin ID SB2026082661
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 14
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 7% Low 93%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 14 vulnerabilities.


1) Resource exhaustion (CVE-ID: CVE-2026-34665)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in the Content Authenticity SDK when handling crafted input. A remote attacker can send specially crafted input to cause a denial of service.


2) Input validation error (CVE-ID: CVE-2026-34666)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the Content Authenticity SDK when parsing crafted input locally. A remote attacker can provide specially crafted input to cause a denial of service.


3) Integer underflow (CVE-ID: CVE-2026-34667)

CWE-ID: CWE-191 - Integer underflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to integer underflow in the Content Authenticity SDK when parsing crafted input locally. A remote attacker can provide specially crafted input to cause a denial of service.


4) Input validation error (CVE-ID: CVE-2026-34668)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the Content Authenticity SDK when parsing crafted input locally. A remote attacker can provide specially crafted input to cause a denial of service.


5) Input validation error (CVE-ID: CVE-2026-34669)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the Content Authenticity SDK when parsing crafted input locally. A remote attacker can provide specially crafted input to cause a denial of service.


6) Input validation error (CVE-ID: CVE-2026-34670)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the Content Authenticity SDK when parsing crafted input locally. A remote attacker can provide specially crafted input to cause a denial of service.


7) Integer overflow (CVE-ID: CVE-2026-34671)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to integer overflow or wraparound in the Content Authenticity SDK when parsing crafted input locally. A remote attacker can provide specially crafted input to cause a denial of service.


8) Integer underflow (CVE-ID: CVE-2026-34672)

CWE-ID: CWE-191 - Integer underflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to integer underflow in the Content Authenticity SDK when parsing crafted input locally. A remote attacker can provide specially crafted input to cause a denial of service.


9) Input validation error (CVE-ID: CVE-2026-34688)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the Content Authenticity SDK when parsing crafted input locally. A remote attacker can provide specially crafted input to cause a denial of service.


10) Resource exhaustion (CVE-ID: CVE-2026-34673)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in the Content Authenticity SDK when parsing crafted input locally. A remote attacker can provide specially crafted input to cause a denial of service.


11) Resource exhaustion (CVE-ID: CVE-2026-34677)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in the Content Authenticity SDK when parsing crafted input locally. A remote attacker can provide specially crafted input to cause a denial of service.


12) Resource exhaustion (CVE-ID: CVE-2026-34678)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in the Content Authenticity SDK when parsing crafted input locally. A remote attacker can provide specially crafted input to cause a denial of service.


13) Input validation error (CVE-ID: CVE-2026-34679)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the Content Authenticity SDK when parsing crafted input locally. A remote attacker can provide specially crafted input to cause a denial of service.


14) Integer overflow (CVE-ID: CVE-2026-34680)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to integer overflow or wraparound in the Content Authenticity SDK when parsing crafted input locally. A remote attacker can provide specially crafted input to cause a denial of service.


Remediation

Install update from vendor's website.