CVE-2026-34679: Adobe c2pa

Medium severity, CVSS 6.2. EPSS: 0.3% chance of exploitation in the next 30 days.

CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

Affected products

  • Adobe c2pa: before 0.80.1 (fixed in 0.80.1)
  • Adobe c2pa-Web: before 0.7.1 (fixed in 0.7.1)

Published 2026-05-12. Last modified 2026-08-28.