type: incident ยท created: 2026-08-01 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: not-rated ยท affected_sectors: [] ยท au_impact: false
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
Summary
Adobe patched CVE-2026-48449 (CVSS 10.0), an incorrect authorization flaw in Campaign Classic (ACC) allowing arbitrary code execution without user interaction, alongside CVE-2026-48448 (CVSS 8.6, SQL injection โ arbitrary file reads).
Key Details
- Date: 2026-08-01
- Source: The Hacker News
- Reliability: Tier 2/4 โ Established cyber journalism
- CVE-2026-48449: CVSS 10.0 โ Incorrect authorization โ arbitrary code execution, no user interaction required
- CVE-2026-48448: CVSS 8.6 โ SQL injection โ arbitrary file reads
- Status: No known in-the-wild exploitation
- Fix Version: ACC v7: 7.4.3 build 9398
Related
- Cve 2026 48449 โ Technical vulnerability page
- Cve 2026 48448 โ Technical vulnerability page