CVE-2026-48449

Published Jul 30, 2026

Last updated 11 hours ago

CVSS critical 10.0
Adobe Campaign Classic

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-48449 identifies an Incorrect Authorization vulnerability within Adobe Campaign Classic (ACC) that could lead to arbitrary code execution in the context of the current user. This flaw affects Adobe Campaign Classic deployments up to and including version 7.4.3 build 9397. Exploitation of this vulnerability does not require user interaction or special privileges, and it can be carried out remotely over a network. The scope of the vulnerability is changed, indicating that successful exploitation can impact components beyond the vulnerable one. Adobe released a security update, APSB26-114, with version 7.4.3 build 9398 containing the fix.

Description
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Source
psirt@adobe.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

psirt@adobe.com
CWE-863

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

1

  1. For defenders, adobe campaign classic flaws put on-prem marketing systems on t… should move fast. Adobe fixed CVE-2026-48449, a CVSS 10.0 Adobe Campaign Classic code execution flaw, and CVE… 🔗 Details → https://t.co/wqO10LcYKu

    @SocXAInvaders

    3 Aug 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 CVE-of-the-Day: CVE-2026-48449 — Adobe Campaign Classic (ACC) CVSS: 10.0 | EPSS: N/A (too new to be scored) An incorrect authorization flaw lets an attacker run arbitrary code as the current user — zero interaction needed. #CVE #infosec #adobe https://t.co/u5Nl61Eb7j

    @YourDailyCVE

    2 Aug 2026

    5 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  3. 1/3 A perfect 10.0 severity flaw hits Adobe Campaign Classic. CVE-2026-48449 lets attackers run code with zero user interaction. If you run this marketing platform, you are exposed until you patch. Are you updated? #CVE #CyberSecurity #ZeroDay #InfoSec #SummerSlam https://t.co/bq

    @CyberTLDR

    2 Aug 2026

    69 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    1 Quote

  4. CVE-2026-48449 - Critical RCE in Adobe Campaign Classic. Incorrect Authorization allows code execution without user interaction. CVSS 10. Unpatched - take immediate action. #CVE #Adobe #infosec #CVEAlert #cybersecurity #devops #devsecops #developer #developers #git #github

    @HugoValters

    1 Aug 2026

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. ⚠️ VULNERABILIDAD CRÍTICA | CVE-2026-48449 en Adobe Campaign Classic: CVSS 10.0 con RCE sin interacción del usuario. Adobe publicó hoy parches de emergencia para Adobe Campaign Classic (ACC), su plataforma de automatización de marketing empresarial, con una vulnerabilida

    @Hackcoder

    1 Aug 2026

    73 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Adobeは、マーケティング自動化製品「Adobe Campaign Classic(ACC)」で最大深刻度となるCVSS 10.0の脆弱性CVE-2026-48449を修正した。この脆弱性は権限管理の不備により、ユーザー操作なしで任意のコード実行が可能と

    @yousukezan

    1 Aug 2026

    1391 Impressions

    1 Retweet

    4 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  7. The Adobe Campaign Classic vulnerability CVE-2026-48449 allows unauthenticated RCE. Adobe also patches eight critical Bridge flaws. Update now. For More: https://t.co/9uDkRjqtag #Adobe #CampaignClassic #CVE #CriticalVulnerability #AdobeBridge #RCE #InfoSec #CyberSecurity https:

    @redsecuretech

    1 Aug 2026

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Adobe patched a maximum severity flaw in Campaign Classic, its enterprise marketing automation platform. CVE-2026-48449 scores a perfect 10.0 on CVSS: incorrect authorization lets an attacker run arbitrary code without any user interaction. A second bug, CVE-2026-48448 (8.6),

    @XavierRiveraX

    1 Aug 2026

    73 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Adobe patched a CVSS 10.0 flaw in Campaign Classic, CVE-2026-48449, that could enable code execution without user interaction. It also fixed CVE-2026-48448, an SQL injection bug tied to file reads. #Adobe #CampaignClassic #CVE202648449 https://t.co/drQQpHHbBV

    @TweetThreatNews

    1 Aug 2026

    203 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🚨 CVSS 10.0 alert Adobe Campaign Classic CVE-2026-48449 Adobe Campaign Classic (on-prem, v7 ≤7.4.3.9397) has a critical unauthenticated RCE flaw (CVE-2026-48449) — no login, no user interaction needed. Paired with a second CVSS 8.6 SQLi bug (CVE-2026-48448), attackers cou

    @techepages

    1 Aug 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 🔒 #CyberSecurity CVE-2026-48449: Adobe Campaign Classic Critical RCE — Detection and Mitigation "Adobe has released out-of-band security patches addressing a critical vulnerability in Adobe…" 🔗 https://t.co/H5MtuZLpjm #CyberSecurity #ThreatIntel #critical #zeroday #

    @SecurityAr58409

    1 Aug 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Warning: 1 critical and 1 high incorrect authorization and sql injection in #Adobe Campaign Classic. #CVE-2026-48449 #CVE-2026-48448 CVSS: 10-8.6. A remote attacker without user interaction can exploit them to execute arbitrary code and gain file system read access. #Patch #Patch

    @CCBalert

    31 Jul 2026

    245 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. 🛡️ #ExploitGrid Daily Threat Digest Top #Vulnerabilities (#CVEs) of the day CVE-2026-48449 CVE-2026-66803 CVE-2026-12946 CVE-2026-13435 CVE-2026-58046 ..🧵👇

    @exploitgrid

    31 Jul 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  14. Adobe published a security advisory for yet another unauthenticated RCE and SQLi that I found in Adobe Campaign. CVE-2026-48449 & CVE-2026-48448: https://t.co/9RdQXUxZtm Many more to come.

    @JamieParfet

    31 Jul 2026

    159 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. Adobe Campaign Classicの脆弱性CVE-2026-48449は、CVSS 10.0レベルでコード実行を可能にする Adobe Campaign Classic CVE-2026-48449 Enables Code Execution at CVSS 10.0 #DailyCyberSecurity (Jul 31) https://t.co/d2TosalLQ3

    @foxbook

    31 Jul 2026

    243 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Adobe Campaign ClassicでCVSSスコア10の脆弱性が修正。CVE-2026-48449認可制御の不備。SQLインジェクションのCVE-2026-48448も修正されている。 https://t.co/teetp4gCHD

    @__kokumoto

    31 Jul 2026

    573 Impressions

    1 Retweet

    2 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  17. Adobe disclosed two high-severity flaws in Adobe Campaign Classic on-premises. CVE-2026-48449 (CVSS 10.0) enables unauthenticated remote code execution via improper authorization. CVE-2026-48448 (CVSS 8.6) permits unauthenticated SQL injection for arbitrary file reads on Windows

    @WorldCyberNewsX

    31 Jul 2026

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. 🚨*CVE* CVE-2026-48449 Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user.… https://t.co/nQQFAMUoCF ----- Traducción: CVE-2026-48449 Ado… https://t.co/utmtNg

    @infoflowcloud

    30 Jul 2026

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.