CVE-2026-48449 is an incorrect authorization flaw (CWE-863) in Adobe Campaign Classic v7, rated CVSS 10.0, allowing unauthenticated, zero-interaction arbitrary code execution.
CVE-2026-48448, a separately patched SQL injection flaw (CVSS 8.6), allows arbitrary file system reads.
Both affect ACC v7 build 9397 and earlier on Windows and Linux; the fix ships in build 9398.
Adobe-hosted instances are already remediated, but on-premises and hybrid deployments require manual patching, and Adobe has not confirmed exploitation in the wild.
Adobe has released a fix for an Adobe Campaign Classic vulnerability that reaches the top of the CVSS scale. Tracked as CVE-2026-48449, the flaw carries a 10.0 rating and stems from incorrect authorization in Adobe’s enterprise marketing automation platform.
Adobe’s advisory states that exploitation requires no authentication and no user interaction, which places any exposed, unpatched instance at immediate risk.
Adobe Campaign Classic sits close to customer records, email infrastructure, integration credentials, and internal data stores, so a flaw of this severity carries operational weight beyond the marketing team. Adobe has not reported exploitation in the wild at the time of disclosure, but a CVSS 10 rating on a network-reachable application is not a detail security teams can defer.
Adobe’s bulletin (APSB26-114) describes CVE-2026-48449 as an incorrect authorization vulnerability that can result in arbitrary code execution in the context of the current user.
According to the CVSS 3.1 vector Adobe published, the flaw is network-exploitable, requires low attack complexity, needs no privileges, needs no user interaction, and has a changed scope, the combination that produces the maximum 10.0 score.
Fixed version: ACC v7, 7.4.3 build 9398 (Windows and Linux)
Adobe has not published exploitation details or a technical write-up of the attack path, and no proof-of-concept was publicly available at the time of the advisory.
Top 10 Cybersecurity Challenges for Enterprises
Enterprises face ten major cybersecurity challenges demanding proactive, layered defense.
A second flaw compounds the exposure
Adobe patched CVE-2026-48448 in the same release. This SQL injection vulnerability carries a CVSS score of 8.6, and Adobe says it can allow arbitrary file system reads. On its own, a file-read vulnerability is a serious finding. Paired with an authorization bypass that needs no credentials, the two flaws raise the stakes for any unpatched instance. Public reporting does not confirm that attackers can chain the two vulnerabilities together.
Adobe’s same update cycle also addressed eight critical-rated flaws in Adobe Bridge, a separate product, covering privilege escalation and arbitrary code execution issues. Those are not part of the Campaign Classic advisory and require separate tracking.
Why Deployment Model Determines Exposure
Adobe-hosted (SaaS) instances — already remediated by Adobe; no customer action required.
Hybrid deployments — the on-premises components remain exposed even though the hosted portion has been fixed.
Security teams should confirm which deployment model applies before assuming the advisory doesn’t apply to them.
Vulnerability
Type
CVSS
Key Operational Risk
CVE-2026-48449
Incorrect authorization
10.0
Unauthenticated, zero-interaction code execution
CVE-2026-48448
SQL injection
8.6
Arbitrary file system read; authentication requirement not specified in available reporting
What to verify before declaring containment
Patching the Adobe Campaign Classic vulnerability closes the exposure going forward, but it does not, by itself, confirm nothing happened before administrators applied the patch. Teams running on-premises or hybrid ACC should:
Confirm the current build number and upgrade any instance at build 9397 or earlier to build 9398.
Review Adobe Campaign Classic application and server logs for unusual authentication bypass attempts, unexpected process execution, or file-read activity predating the patch.
Check service accounts and integration credentials tied to Campaign Classic for unexpected use.
Confirm affected servers are patched. Verify that administering endpoints run current security updates too. Server patching and endpoint patching are not the same control.
Featured resource
Cybersecurity kit
Download a complete cybersecurity kit with blueprints, frameworks, checklists, policy templates, and UEM guidance.
Hexnode does not monitor Adobe Campaign Classic directly, ingest its application logs, or detect exploitation of this Adobe Campaign Classic vulnerability. Its role covers only the endpoints that administer or connect to Campaign Classic environments, not the application itself.
Before a patch is applied:Hexnode UEM can enforce patch and configuration compliance on managed Windows endpoints, as well as configuration and script-based compliance on Linux endpoints used to administer Campaign Classic.
During investigation:Hexnode XDR can investigate suspicious activity on managed endpoints, primarily Windows and macOS, and cross-reference endpoint telemetry with findings from Campaign Classic log review and identity security tools.
These capabilities complement, rather than replace, Adobe’s patch, application-level log analysis, and identity review. Hexnode does not patch Adobe Campaign Classic or provide server-side application monitoring.
FAQs
Is Adobe Campaign Classic’s hosted (SaaS) offering affected?
No. Adobe has already remediated its hosted instances; the advisory applies to fully on-premises deployments and the on-premises components of hybrid deployments.
Does the absence of confirmed exploitation mean organizations can wait to patch?
No. Adobe has not confirmed exploitation in the wild, but a CVSS 10.0, unauthenticated, zero-interaction flaw warrants immediate patching, since public disclosure can accelerate exploit development.
Should teams check anything beyond the Campaign Classic server itself?
Yes. Review integration credentials and service accounts connected to Campaign Classic, and confirm administrative endpoints are running current security updates, in addition to upgrading the application itself.
Conclusion
This Adobe Campaign Classic vulnerability’s CVSS 10 score, lack of authentication requirement, and lack of user interaction leave little margin for delay on exposed, on-premises deployments. Organizations should confirm their deployment model, apply build 9398, and review logs and credentials for signs of activity that predates the fix.
Closing the vulnerability is the first step, not the last. Verifying that administrative endpoints are current, credentials are clean, and no unexplained activity occurred before the patch will help increase confidence in containment.
Strengthen Patch Compliance Across Managed Endpoints
Enforce consistent patch and access policies across the devices your teams use to manage critical applications.
A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions—without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable—politely.