Synced 30 Sept 2026 23:45 UTC Account
← All products

CVE-2026-48287

HIGH severity · CVSS 7.4 · Untrusted search path
7.4CVSS HIGH

Summary

CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.

Impact & exploitability

Attack vectorLocal
Attack complexityHigh
Privileges requiredNone
User interactionRequired
Confidentiality impactHigh
Integrity impactHigh
Availability impactNone
Exploit probability (EPSS)0%

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N

Affected products we track (4)

Recommendation

Apply the vendor fix promptly. Open any affected product above for its exact safe version.