Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-01 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: not-rated ยท affected_sectors: [] ยท au_impact: false

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Summary

Adobe patched CVE-2026-48449 (CVSS 10.0), an incorrect authorization flaw in Campaign Classic (ACC) allowing arbitrary code execution without user interaction, alongside CVE-2026-48448 (CVSS 8.6, SQL injection โ†’ arbitrary file reads).

Key Details

  • Date: 2026-08-01
  • Source: The Hacker News
  • Reliability: Tier 2/4 โ€” Established cyber journalism
  • CVE-2026-48449: CVSS 10.0 โ€” Incorrect authorization โ†’ arbitrary code execution, no user interaction required
  • CVE-2026-48448: CVSS 8.6 โ€” SQL injection โ†’ arbitrary file reads
  • Status: No known in-the-wild exploitation
  • Fix Version: ACC v7: 7.4.3 build 9398

Related

Sources