Path traversal in Adobe products - CVE-2026-48442
Published: August 14, 2026
Vulnerability identifier: #VU142511
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-48442
CWE-ID: CWE-22
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to write arbitrary files to the file system.
The vulnerability exists due to path traversal in the Content Credentials SDK when handling file paths. A remote attacker can supply a crafted pathname to write arbitrary files to the file system.
Affected software
C2PA Tool
Content Credentials JS SDK
Content Credentials Rust SDK
Content Credentials JS SDK
Content Credentials Rust SDK
How to mitigate CVE-2026-48442
Install security update from vendor's website.
C2PA Tool - update to 0.27.6
Content Credentials JS SDK - update to 0.12.1
Content Credentials Rust SDK - update to 0.90.6
Content Credentials JS SDK - update to 0.12.1
Content Credentials Rust SDK - update to 0.90.6