CVE-2026-48290

CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:adobe:c2pa:*:*:*:*:*:rust:*:*
cpe:2.3:a:adobe:c2pa-web:*:*:*:*:*:node.js:*:*
cpe:2.3:a:adobe:c2patool:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-14 22:17

Updated : 2026-08-28 00:17


NVD link : CVE-2026-48290

Mitre link : CVE-2026-48290

CVE.ORG link : CVE-2026-48290


JSON object : View

Products Affected

apple

  • iphone_os
  • macos

microsoft

  • windows

adobe

  • c2pa
  • c2pa-web
  • c2patool

linux

  • linux_kernel

google

  • android
CWE
CWE-918

Server-Side Request Forgery (SSRF)