CVE-2026-48298: CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)
Published Jul 14, 2026
·Updated
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Affected Software
9 affected components
CAI Content Credentials
All of the following
Any of the following
Adobe C2pa Rust<=0.84.0
Adobe C2pa-web Node.js<=0.7.0
Adobe C2patool<=0.17.0
Any of the following
Apple iPhone OS
Apple macOS
Google Android
Linux Linux kernel
Microsoft Windows
Event History
Jul 14, 2026
CVE Published
via MITRE·09:32 PM
Data Sourced
via MITRE·09:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48298?
CVE-2026-48298 has a severity rating of medium with a score of 6.2.
2
How do I fix CVE-2026-48298?
To fix CVE-2026-48298, users should upgrade to the latest patched version of CAI Content Credentials.
3
What type of vulnerability is CVE-2026-48298?
CVE-2026-48298 is classified as an Integer Underflow (Wrap or Wraparound) vulnerability.
4
What are the potential impacts of CVE-2026-48298?
Exploiting CVE-2026-48298 can lead to an application denial-of-service condition.
5
Which software is affected by CVE-2026-48298?
CVE-2026-48298 affects CAI Content Credentials.