SYS::ONLINE
Wasteland.
Briefs1223
Issues19
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-48303 2026-06-09

CVE-2026-48303: Critical Authorization Flaw in Adobe Campaign Classic Enables Remote Code Execution

"A maximum-severity (CVSS 10.0) Incorrect Authorization vulnerability in Adobe Campaign Classic allows unauthenticated attackers to execute arbitrary code over the network without user interaction."

A maximum-severity (CVSS 10.0) Incorrect Authorization vulnerability in Adobe Campaign Classic allows unauthenticated attackers to execute arbitrary code over the network without user interaction.

What Is It

CVE-2026-48303 is an Incorrect Authorization vulnerability (CWE-863) in Adobe Campaign Classic (ACC). Adobe's PSIRT reports that the flaw could result in arbitrary code execution in the context of the current user. Exploitation requires no user interaction, and the vulnerability carries a changed scope, meaning a successful attack can affect resources beyond the initially vulnerable component.

The CVSS 3.1 base score is 10.0 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, network-accessible, low attack complexity, no privileges required, and high impact to confidentiality, integrity, and availability.

Why It Matters

A perfect 10.0 score is rare and reflects the worst-case combination of conditions: an attacker can reach the system over the network, needs no credentials, and requires no victim interaction. Because the scope is changed and impact is high across all three security dimensions, successful exploitation could grant full control over affected systems and adjacent resources. Adobe Campaign Classic is a marketing automation platform that frequently holds large volumes of customer data, making it a high-value target.

What's Vulnerable

Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected. No specific affected CPE configurations were enumerated in the supplied NVD record.

Patch Status

Adobe has published a security bulletin (APSB26-66) addressing this vulnerability. Administrators should consult Adobe's advisory and upgrade affected ACC instances beyond version 7.4.3 build 9394.

The supplied source material contains no CISA KEV entry for this CVE, so there is no confirmation of active exploitation in the wild at this time.

Sources