SYS::ONLINE
Wasteland.
Briefs1616
Issues21
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-48449 2026-07-30

CVE-2026-48449: Adobe Campaign Classic Authorization Flaw Rated CVSS 10.0

"Adobe has disclosed a critical Incorrect Authorization vulnerability in Adobe Campaign Classic that, per the vendor advisory, could result in arbitrary code execution. Adobe states that exploitation does not require…"

Adobe has disclosed a critical Incorrect Authorization vulnerability in Adobe Campaign Classic that, per the vendor advisory, could result in arbitrary code execution. Adobe states that exploitation does not require user interaction, and the assigned CVSS vector indicates the flaw is network-reachable and requires no privileges.

What Is It

CVE-2026-48449 is an Incorrect Authorization flaw (CWE-863) in Adobe Campaign Classic (ACC). Per Adobe's advisory, the issue "could result in arbitrary code execution in the context of the current user," and exploitation "does not require user interaction."

The vulnerability carries a CVSS 3.1 base score of 10.0 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. That breaks down to network-reachable, low attack complexity, no privileges required, no user interaction, and high impact to confidentiality, integrity, and availability. Scope is changed, meaning the flaw can affect resources beyond the vulnerable component itself.

Note that the advisory's phrasing, code execution "in the context of the current user", and the vector's PR:N (no privileges required) describe the issue at different levels of detail. Adobe has not published technical detail on the attack path, so the precise preconditions for exploitation are not publicly established beyond what the vector asserts.

Why It Matters

A CVSS 10.0 is the maximum possible score, and the vector explains why: every exploitability metric is at its worst case. As scored, an attacker needs no credentials, no victim interaction, and no local foothold; only network access to an affected instance. The changed scope indicates impact can spread past the ACC component boundary.

Adobe Campaign Classic is a marketing automation platform that typically holds large customer datasets and integrates with surrounding systems, which raises the value of the confidentiality and integrity impact.

What's Vulnerable

Per Adobe's affected-product data:

No CPE entries were published in the NVD record at the time of writing.

Patch Status

Adobe has shipped a fix. Build 7.4.3 build 9398 is listed as unaffected; upgrading to that build or later is the remediation path. Full details are in Adobe security bulletin APSB26-114.

The NVD record was published 2026-07-30 and remains in Received status, so NVD enrichment (CPE mapping, secondary scoring) is not yet complete. As of publication, CVE-2026-48449 does not appear in CISA's Known Exploited Vulnerabilities catalog (linked below), and there is no public confirmation of active exploitation. Because KEV listing is what triggers BOD 22-01 obligations, no federal remediation deadline currently applies to this CVE, a status that can change if exploitation is later observed, so defenders should re-check the catalog rather than treat its absence as durable.

Sources