CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in an arbitrary file system write. An attacker could leverage this vulnerability to write to unauthorized files or directories outside of intended restrictions. Exploitation of this issue requires user interaction in that a victim must extract a maliciously crafted file.
References
| Link | Resource |
|---|---|
| https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-61.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
15 Jun 2026, 15:08
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Apple macos
Linux Google android Apple Linux linux Kernel Microsoft windows Adobe Adobe c2pa Microsoft Adobe c2pa-web Apple iphone Os |
|
| CPE | cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:* cpe:2.3:a:adobe:c2pa:*:*:*:*:*:rust:*:* cpe:2.3:a:adobe:c2pa-web:*:*:*:*:*:node.js:*:* cpe:2.3:o:google:android:-:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* |
|
| References | () https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-61.html - Vendor Advisory |
09 Jun 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-09 22:16
Updated : 2026-06-15 15:08
NVD link : CVE-2026-34657
Mitre link : CVE-2026-34657
CVE.ORG link : CVE-2026-34657
JSON object : View
Products Affected
adobe
- c2pa
- c2pa-web
microsoft
- windows
- android
linux
- linux_kernel
apple
- macos
- iphone_os
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
