CVE-2026-48438
Analyzed Analyzed - Analysis Complete

NULL Pointer Dereference in CAI Content Credentials

Vulnerability report for CVE-2026-48438, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-28

Assigner: Adobe Systems Incorporated

Description

CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-28
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-30
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
adobe c2pa to 0.90.6 (exc)
adobe c2pa-web to 0.12.1 (exc)
adobe c2patool to 0.27.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a NULL Pointer Dereference vulnerability in CAI Content Credentials that could cause an application to crash. An attacker can exploit it to trigger a denial-of-service condition without needing any user interaction.

Detection Guidance

Detection of this NULL Pointer Dereference vulnerability in CAI Content Credentials may require application-specific monitoring for crashes or denial-of-service conditions. Check application logs for unexpected terminations or errors related to content processing. No specific commands are provided in the available context.

Impact Analysis

The vulnerability could allow an attacker to crash the application, making it unavailable for legitimate users. This disrupts normal operations and may lead to service interruptions.

Compliance Impact

This vulnerability causes a denial-of-service by crashing the application, which could disrupt services handling sensitive data. For GDPR, this may impact availability of personal data processing systems, potentially violating Article 32 requirements for resilience. For HIPAA, it could disrupt systems managing protected health information, affecting integrity and availability controls under the Security Rule.

Mitigation Strategies

Apply the latest security patches or updates provided by Adobe for CAI Content Credentials to address the NULL Pointer Dereference vulnerability. Monitor official Adobe advisories for patches and ensure all systems using the affected software are updated promptly.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-48438. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart