A maximum-severity (CVSS 10.0) Incorrect Authorization vulnerability in Adobe Campaign Classic allows unauthenticated attackers to execute arbitrary code over the network without user interaction.
What Is It
CVE-2026-48303 is an Incorrect Authorization vulnerability (CWE-863) in Adobe Campaign Classic (ACC). Adobe's PSIRT reports that the flaw could result in arbitrary code execution in the context of the current user. Exploitation requires no user interaction, and the vulnerability carries a changed scope, meaning a successful attack can affect resources beyond the initially vulnerable component.
The CVSS 3.1 base score is 10.0 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, network-accessible, low attack complexity, no privileges required, and high impact to confidentiality, integrity, and availability.
Why It Matters
A perfect 10.0 score is rare and reflects the worst-case combination of conditions: an attacker can reach the system over the network, needs no credentials, and requires no victim interaction. Because the scope is changed and impact is high across all three security dimensions, successful exploitation could grant full control over affected systems and adjacent resources. Adobe Campaign Classic is a marketing automation platform that frequently holds large volumes of customer data, making it a high-value target.
What's Vulnerable
Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected. No specific affected CPE configurations were enumerated in the supplied NVD record.
Patch Status
Adobe has published a security bulletin (APSB26-66) addressing this vulnerability. Administrators should consult Adobe's advisory and upgrade affected ACC instances beyond version 7.4.3 build 9394.
The supplied source material contains no CISA KEV entry for this CVE, so there is no confirmation of active exploitation in the wild at this time.