CVE-2026-34657
Estado: AnalizadaMedia (5.5)—
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in an arbitrary file system write. An attacker could leverage this vulnerability to write to unauthorized files or directories outside of intended restrictions. Exploitation of this issue requires user interaction in that a victim must extract a maliciously crafted file.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.29%
- Percentil entre todas las CVEs puntuadas: 20
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-22
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-34657",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-34657",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-06-10T14:25:32.622105Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@adobe.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "psirt@adobe.com",
"affectedData": [
{
"vendor": "Adobe",
"product": "Content Credentials Rust SDK",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "c2pa-v0.80.1"
},
{
"status": "unaffected",
"version": "c2pa-v0.85.1",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Adobe",
"product": "Content Credentials JS SDK",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "@contentauth/c2pa-web@0.7.1"
},
{
"status": "unaffected",
"version": "@contentauth/c2pa-web@0.8.3",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-06-09T22:16:22.787",
"references": [
{
"url": "https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-61.html",
"tags": [
"Vendor Advisory"
],
"source": "psirt@adobe.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@adobe.com",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in an arbitrary file system write. An attacker could leverage this vulnerability to write to unauthorized files or directories outside of intended restrictions. Exploitation of this issue requires user interaction in that a victim must extract a maliciously crafted file."
},
{
"lang": "es",
"value": "Las versiones c2pa-web@0.7.1, c2pa-v0.80.1 y anteriores de CAI Content Credentials están afectadas por una vulnerabilidad de Limitación Inadecuada de un Nombre de Ruta a un Directorio Restringido ('Salto de Ruta') que podría resultar en una escritura arbitraria en el sistema de archivos. Un atacante podría aprovechar esta vulnerabilidad para escribir en archivos o directorios no autorizados fuera de las restricciones previstas. La explotación de este problema requiere interacción del usuario en el que una víctima debe extraer un archivo maliciosamente elaborado."
}
],
"lastModified": "2026-08-28T00:17:19.990",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:adobe:c2pa:*:*:*:*:*:rust:*:*",
"vulnerable": true,
"matchCriteriaId": "FAC5EB4E-D740-4724-82DA-7C49F0138397",
"versionEndIncluding": "0.80.1"
},
{
"criteria": "cpe:2.3:a:adobe:c2pa-web:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "4402A37D-5CCD-46EB-8942-3BA694C3F770",
"versionEndIncluding": "0.7.1"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B5415705-33E5-46D5-8E4D-9EBADC8C5705"
},
{
"criteria": "cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "387021A0-AF36-463C-A605-32EA7DAC172E"
},
{
"criteria": "cpe:2.3:o:google:android:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F8B9FEC8-73B6-43B8-B24E-1F7C20D91D26"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"
},
{
"criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "psirt@adobe.com"
}