CVE-2026-48449
Published Jul 30, 2026
Last updated 11 hours ago
AI description
CVE-2026-48449 identifies an Incorrect Authorization vulnerability within Adobe Campaign Classic (ACC) that could lead to arbitrary code execution in the context of the current user. This flaw affects Adobe Campaign Classic deployments up to and including version 7.4.3 build 9397. Exploitation of this vulnerability does not require user interaction or special privileges, and it can be carried out remotely over a network. The scope of the vulnerability is changed, indicating that successful exploitation can impact components beyond the vulnerable one. Adobe released a security update, APSB26-114, with version 7.4.3 build 9398 containing the fix.
- Description
- Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
- Source
- psirt@adobe.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 10
- Impact score
- 6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- psirt@adobe.com
- CWE-863
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
1
For defenders, adobe campaign classic flaws put on-prem marketing systems on t… should move fast. Adobe fixed CVE-2026-48449, a CVSS 10.0 Adobe Campaign Classic code execution flaw, and CVE… 🔗 Details → https://t.co/wqO10LcYKu
@SocXAInvaders
3 Aug 2026
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-of-the-Day: CVE-2026-48449 — Adobe Campaign Classic (ACC) CVSS: 10.0 | EPSS: N/A (too new to be scored) An incorrect authorization flaw lets an attacker run arbitrary code as the current user — zero interaction needed. #CVE #infosec #adobe https://t.co/u5Nl61Eb7j
@YourDailyCVE
2 Aug 2026
5 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
1/3 A perfect 10.0 severity flaw hits Adobe Campaign Classic. CVE-2026-48449 lets attackers run code with zero user interaction. If you run this marketing platform, you are exposed until you patch. Are you updated? #CVE #CyberSecurity #ZeroDay #InfoSec #SummerSlam https://t.co/bq
@CyberTLDR
2 Aug 2026
69 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
1 Quote
CVE-2026-48449 - Critical RCE in Adobe Campaign Classic. Incorrect Authorization allows code execution without user interaction. CVSS 10. Unpatched - take immediate action. #CVE #Adobe #infosec #CVEAlert #cybersecurity #devops #devsecops #developer #developers #git #github
@HugoValters
1 Aug 2026
30 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ VULNERABILIDAD CRÍTICA | CVE-2026-48449 en Adobe Campaign Classic: CVSS 10.0 con RCE sin interacción del usuario. Adobe publicó hoy parches de emergencia para Adobe Campaign Classic (ACC), su plataforma de automatización de marketing empresarial, con una vulnerabilida
@Hackcoder
1 Aug 2026
73 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Adobeは、マーケティング自動化製品「Adobe Campaign Classic(ACC)」で最大深刻度となるCVSS 10.0の脆弱性CVE-2026-48449を修正した。この脆弱性は権限管理の不備により、ユーザー操作なしで任意のコード実行が可能と
@yousukezan
1 Aug 2026
1391 Impressions
1 Retweet
4 Likes
1 Bookmark
0 Replies
0 Quotes
The Adobe Campaign Classic vulnerability CVE-2026-48449 allows unauthenticated RCE. Adobe also patches eight critical Bridge flaws. Update now. For More: https://t.co/9uDkRjqtag #Adobe #CampaignClassic #CVE #CriticalVulnerability #AdobeBridge #RCE #InfoSec #CyberSecurity https:
@redsecuretech
1 Aug 2026
46 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Adobe patched a maximum severity flaw in Campaign Classic, its enterprise marketing automation platform. CVE-2026-48449 scores a perfect 10.0 on CVSS: incorrect authorization lets an attacker run arbitrary code without any user interaction. A second bug, CVE-2026-48448 (8.6),
@XavierRiveraX
1 Aug 2026
73 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Adobe patched a CVSS 10.0 flaw in Campaign Classic, CVE-2026-48449, that could enable code execution without user interaction. It also fixed CVE-2026-48448, an SQL injection bug tied to file reads. #Adobe #CampaignClassic #CVE202648449 https://t.co/drQQpHHbBV
@TweetThreatNews
1 Aug 2026
203 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVSS 10.0 alert Adobe Campaign Classic CVE-2026-48449 Adobe Campaign Classic (on-prem, v7 ≤7.4.3.9397) has a critical unauthenticated RCE flaw (CVE-2026-48449) — no login, no user interaction needed. Paired with a second CVSS 8.6 SQLi bug (CVE-2026-48448), attackers cou
@techepages
1 Aug 2026
38 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-48449: Adobe Campaign Classic Critical RCE — Detection and Mitigation "Adobe has released out-of-band security patches addressing a critical vulnerability in Adobe…" 🔗 https://t.co/H5MtuZLpjm #CyberSecurity #ThreatIntel #critical #zeroday #
@SecurityAr58409
1 Aug 2026
42 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Warning: 1 critical and 1 high incorrect authorization and sql injection in #Adobe Campaign Classic. #CVE-2026-48449 #CVE-2026-48448 CVSS: 10-8.6. A remote attacker without user interaction can exploit them to execute arbitrary code and gain file system read access. #Patch #Patch
@CCBalert
31 Jul 2026
245 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ #ExploitGrid Daily Threat Digest Top #Vulnerabilities (#CVEs) of the day CVE-2026-48449 CVE-2026-66803 CVE-2026-12946 CVE-2026-13435 CVE-2026-58046 ..🧵👇
@exploitgrid
31 Jul 2026
45 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Adobe published a security advisory for yet another unauthenticated RCE and SQLi that I found in Adobe Campaign. CVE-2026-48449 & CVE-2026-48448: https://t.co/9RdQXUxZtm Many more to come.
@JamieParfet
31 Jul 2026
159 Impressions
0 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
Adobe Campaign Classicの脆弱性CVE-2026-48449は、CVSS 10.0レベルでコード実行を可能にする Adobe Campaign Classic CVE-2026-48449 Enables Code Execution at CVSS 10.0 #DailyCyberSecurity (Jul 31) https://t.co/d2TosalLQ3
@foxbook
31 Jul 2026
243 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Adobe Campaign ClassicでCVSSスコア10の脆弱性が修正。CVE-2026-48449認可制御の不備。SQLインジェクションのCVE-2026-48448も修正されている。 https://t.co/teetp4gCHD
@__kokumoto
31 Jul 2026
573 Impressions
1 Retweet
2 Likes
2 Bookmarks
0 Replies
0 Quotes
Adobe disclosed two high-severity flaws in Adobe Campaign Classic on-premises. CVE-2026-48449 (CVSS 10.0) enables unauthenticated remote code execution via improper authorization. CVE-2026-48448 (CVSS 8.6) permits unauthenticated SQL injection for arbitrary file reads on Windows
@WorldCyberNewsX
31 Jul 2026
17 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨*CVE* CVE-2026-48449 Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user.… https://t.co/nQQFAMUoCF ----- Traducción: CVE-2026-48449 Ado… https://t.co/utmtNg
@infoflowcloud
30 Jul 2026
49 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes