CVE-2026-47903: CAI Content Credentials | Improper Input Validation (CWE-20)
Published Jun 9, 2026
·Updated
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Input Validation vulnerability. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Affected Software
4 affected components
npm/c2pa-web<=0.7.1
npm/c2pa-v<=0.80.1
Adobe C2pa Rust<=0.80.1
Adobe C2pa-web Node.js<=0.7.1
Event History
Jun 9, 2026
CVE Published
via MITRE·09:21 PM
Data Sourced
via MITRE·09:21 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-47903?
The severity of CVE-2026-47903 is medium with a score of 6.2.
2
How do I fix CVE-2026-47903?
To fix CVE-2026-47903, upgrade to CAI Content Credentials versions c2pa-web@0.8.0 or later.
3
What is the impact of CVE-2026-47903?
CVE-2026-47903 can lead to a denial-of-service condition by crashing the application.
4
What products are affected by CVE-2026-47903?
CVE-2026-47903 affects CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier.
5
What kind of vulnerability is CVE-2026-47903?
CVE-2026-47903 is an Improper Input Validation vulnerability categorized under CWE-20.