CVE-2026-34712: Adobe c2pa

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Input Validation vulnerability. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

Affected products

  • Adobe c2pa: up to and including 0.80.1
  • Adobe c2pa-Web: up to and including 0.7.1

Published 2026-06-09. Last modified 2026-08-28.