type: cve ยท created: 2026-08-01 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: not-rated ยท severity: critical ยท affected_sectors: [] ยท au_impact: false
CVE-2026-48449
Summary
CVE-2026-48449 is a critical incorrect authorization vulnerability in Adobe Campaign Classic (ACC) rated CVSS 10.0. The flaw allows arbitrary code execution without user interaction.
Details
This maximum-severity vulnerability in Adobe Campaign Classic stems from an incorrect authorization flaw that allows remote code execution without requiring any user interaction. It was patched alongside CVE-2026-48448 (CVSS 8.6, SQL injection) in ACC version 7: 7.4.3 build 9398. No known in-the-wild exploitation has been reported as of disclosure.
Remediation
Update to Adobe Campaign Classic v7: 7.4.3 build 9398 or later.
Related
- Cve 2026 48448 โ SQL injection in the same product
- Adobe Campaign Classic Cvss 10 0 Flaw Could Run Code Without User Interaction โ Incident coverage