CVE-2026-47922
Analyzed Analyzed - Analysis Complete

CAI Content Credentials Server-Side Request Forgery Vulnerability

Vulnerability report for CVE-2026-47922, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-28

Assigner: Adobe Systems Incorporated

Description

CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-28
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-30
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
adobe c2pa to 0.90.6 (exc)
adobe c2pa-web to 0.12.1 (exc)
adobe c2patool to 0.27.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Server-Side Request Forgery (SSRF) vulnerability in CAI Content Credentials that could allow an attacker to make unauthorized requests from the server. It requires user interaction, such as visiting a malicious URL or interacting with a compromised webpage, to exploit. The scope is changed, meaning the impact may extend beyond the vulnerable component.

Detection Guidance

Detection requires monitoring network traffic for unusual outbound requests from CAI Content Credentials. Check logs for SSRF indicators like unexpected HTTP requests to internal systems or unusual URL parsing behavior. No specific commands are provided in the context.

Impact Analysis

An attacker could exploit this to perform unauthorized actions on your behalf, such as accessing internal systems or making requests to other services. Since it requires user interaction, you would need to click a malicious link or visit a compromised site for the attack to succeed.

Compliance Impact

The SSRF vulnerability in CAI Content Credentials could potentially lead to unauthorized access or data exfiltration, which may impact compliance with GDPR or HIPAA if sensitive data is exposed. However, the provided CVE details do not explicitly address compliance implications.

Mitigation Strategies

Apply patches or updates from Adobe if available. Restrict outbound network access for CAI Content Credentials to trusted domains. Monitor for suspicious activity and disable the service if exploitation is suspected.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47922. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart