CVE-2026-48287: CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on c
CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-48287
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-482870.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-48287 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for CAI Content Credentials
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-48357: CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that…nvd · 2026-07-14
- mediumCVE-2026-48354: CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that co…nvd · 2026-07-14
- mediumCVE-2026-48353: CAI Content Credentials is affected by an Improper Input Validation vulnerability that could l…nvd · 2026-07-14
- highCVE-2026-48352: CAI Content Credentials is affected by an Improper Input Validation vulnerability that could r…nvd · 2026-07-14
- highCVE-2026-48351: CAI Content Credentials is affected by an Improper Input Validation vulnerability that could r…nvd · 2026-07-14
- mediumCVE-2026-48312: CAI Content Credentials is affected by an Improper Input Validation vulnerability that could r…nvd · 2026-07-14
More from NVD Recent CVEs
- unknownCVE-2026-69075: FlowIntel is affected by a stored cross-site scripting vulnerability through multiple user-con…2026-08-03
- mediumCVE-2026-63563: Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped wit…2026-08-03
- lowCVE-2026-63545: Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and …2026-08-03
- mediumCVE-2026-62416: Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the ini…2026-08-03
- mediumCVE-2026-60011: Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to dir…2026-08-03