CVE-2026-76198: CAI Content Credentials | Improper Input Validation (CWE-20)
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What must an attacker do to exploit this issue?
The attacker must craft a malicious file and convince a victim to open it. The vulnerability has local attack vector and requires user interaction.
What is the potential impact if exploitation succeeds?
Successful exploitation could allow arbitrary file system reads, including access to sensitive files and directories outside the intended access scope. The provided impact information indicates confidentiality impact only; integrity and availability are not affected.