CVE-2026-89277
Awaiting Analysis Awaiting Analysis - Queue

CAI Content Credentials Integer Overflow Denial-of-Service

Vulnerability report for CVE-2026-89277, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-22

Last updated on: 2026-09-22

Assigner: Adobe Systems Incorporated

Description

CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-22
Last Modified
2026-09-22
Generated
2026-09-22
AI Q&A
2026-09-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
adobe cai_content_credentials *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-190 The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Integer Overflow or Wraparound issue in CAI Content Credentials that could cause an application denial-of-service. An attacker can exploit it to crash the application by making a victim visit a specially crafted URL or interact with a compromised web page.

Detection Guidance

Detection may involve monitoring for application crashes or unusual behavior when processing CAI Content Credentials. Check logs for errors related to integer overflow or denial-of-service events. No specific commands are provided in the context.

Impact Analysis

If exploited, this vulnerability could crash the application you are using, preventing you from accessing its features. This may disrupt your workflow or access to important data, especially if the application is critical for your tasks.

Compliance Impact

This vulnerability could impact compliance by causing application denial-of-service, potentially disrupting access to critical data or systems. For GDPR, this may affect availability of personal data processing systems. For HIPAA, it could interfere with electronic protected health information access. However, specific compliance impacts depend on system context and mitigations in place.

Mitigation Strategies

Apply patches or updates from Adobe if available. Restrict user interaction with untrusted URLs or web pages. Monitor application stability and disable CAI Content Credentials if exploitation is suspected.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89277. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart