CVE-2026-48287: CAI Content Credentials | Untrusted Search Path (CWE-426)
CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48287?
CVE-2026-48287 has a severity rating of high, with a score of 7.4.
How do I fix CVE-2026-48287?
To address CVE-2026-48287, ensure to update the CAI Content Credentials to the latest version provided by the vendor.
What are the implications of CVE-2026-48287?
Exploiting CVE-2026-48287 could allow an attacker to execute arbitrary code in the context of the current user.
Is user interaction necessary to exploit CVE-2026-48287?
Yes, exploitation of CVE-2026-48287 requires user interaction, such as the victim visiting a malicious site.
What does the term 'untrusted search path' mean in CVE-2026-48287?
In the context of CVE-2026-48287, 'untrusted search path' refers to a vulnerability where the software may load unverified dynamic-link libraries, potentially allowing code execution.