type: cve ยท created: 2026-08-01 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: not-rated ยท severity: high ยท affected_sectors: [] ยท au_impact: false
CVE-2026-48448
Summary
CVE-2026-48448 is a SQL injection vulnerability in Adobe Campaign Classic (ACC) rated CVSS 8.6. The flaw allows arbitrary file reads via SQL injection.
Details
This SQL injection vulnerability in Adobe Campaign Classic enables an attacker to read arbitrary files from the server. It was patched alongside CVE-2026-48449 (CVSS 10.0) in ACC version 7: 7.4.3 build 9398. No known in-the-wild exploitation has been reported.
Remediation
Update to Adobe Campaign Classic v7: 7.4.3 build 9398 or later.
Related
- Cve 2026 48449 โ Critical incorrect authorization flaw in the same product
- Adobe Campaign Classic Cvss 10 0 Flaw Could Run Code Without User Interaction โ Incident coverage