Sophia
Hart

Adobe Campaign Classic Vulnerability: Inside CVE-2026-48449’s CVSS 10 Flaw

Sophia Hart

Aug 5, 2026

5 min read

adobe campaign classic vulnerability

TL; DR

  • CVE-2026-48449 is an incorrect authorization flaw (CWE-863) in Adobe Campaign Classic v7, rated CVSS 10.0, allowing unauthenticated, zero-interaction arbitrary code execution.
  • CVE-2026-48448, a separately patched SQL injection flaw (CVSS 8.6), allows arbitrary file system reads.
  • Both affect ACC v7 build 9397 and earlier on Windows and Linux; the fix ships in build 9398.
  • Adobe-hosted instances are already remediated, but on-premises and hybrid deployments require manual patching, and Adobe has not confirmed exploitation in the wild.

Adobe has released a fix for an Adobe Campaign Classic vulnerability that reaches the top of the CVSS scale. Tracked as CVE-2026-48449, the flaw carries a 10.0 rating and stems from incorrect authorization in Adobe’s enterprise marketing automation platform.

Adobe’s advisory states that exploitation requires no authentication and no user interaction, which places any exposed, unpatched instance at immediate risk.

Adobe Campaign Classic sits close to customer records, email infrastructure, integration credentials, and internal data stores, so a flaw of this severity carries operational weight beyond the marketing team. Adobe has not reported exploitation in the wild at the time of disclosure, but a CVSS 10 rating on a network-reachable application is not a detail security teams can defer.

Book a free demo and explore Hexnode today!

What Adobe’s advisory confirms

Adobe’s bulletin (APSB26-114) describes CVE-2026-48449 as an incorrect authorization vulnerability that can result in arbitrary code execution in the context of the current user.

According to the CVSS 3.1 vector Adobe published, the flaw is network-exploitable, requires low attack complexity, needs no privileges, needs no user interaction, and has a changed scope, the combination that produces the maximum 10.0 score.

Key confirmed details:

  • Vulnerability type: Incorrect authorization (CWE-863)
  • CVSS score: 10.0 (CVSS 3.1)
  • Authentication required: None
  • User interaction required: None
  • Disclosed: July 30, 2026
  • Fixed version: ACC v7, 7.4.3 build 9398 (Windows and Linux)

Adobe has not published exploitation details or a technical write-up of the attack path, and no proof-of-concept was publicly available at the time of the advisory.

A second flaw compounds the exposure

Adobe patched CVE-2026-48448 in the same release. This SQL injection vulnerability carries a CVSS score of 8.6, and Adobe says it can allow arbitrary file system reads. On its own, a file-read vulnerability is a serious finding. Paired with an authorization bypass that needs no credentials, the two flaws raise the stakes for any unpatched instance. Public reporting does not confirm that attackers can chain the two vulnerabilities together.

Adobe’s same update cycle also addressed eight critical-rated flaws in Adobe Bridge, a separate product, covering privilege escalation and arbitrary code execution issues. Those are not part of the Campaign Classic advisory and require separate tracking.

Why Deployment Model Determines Exposure

  • Adobe-hosted (SaaS) instances — already remediated by Adobe; no customer action required.
  • Fully on-premises deployments — directly exposed until administrators apply build 9398.
  • Hybrid deployments — the on-premises components remain exposed even though the hosted portion has been fixed.

Security teams should confirm which deployment model applies before assuming the advisory doesn’t apply to them.

Vulnerability Type CVSS Key Operational Risk
CVE-2026-48449 Incorrect authorization 10.0 Unauthenticated, zero-interaction code execution
CVE-2026-48448 SQL injection 8.6 Arbitrary file system read; authentication requirement not specified in available reporting

What to verify before declaring containment

Patching the Adobe Campaign Classic vulnerability closes the exposure going forward, but it does not, by itself, confirm nothing happened before administrators applied the patch. Teams running on-premises or hybrid ACC should:

  • Confirm the current build number and upgrade any instance at build 9397 or earlier to build 9398.
  • Review Adobe Campaign Classic application and server logs for unusual authentication bypass attempts, unexpected process execution, or file-read activity predating the patch.
  • Check service accounts and integration credentials tied to Campaign Classic for unexpected use.
  • Confirm affected servers are patched. Verify that administering endpoints run current security updates too. Server patching and endpoint patching are not the same control.
cybersecurity kit
Featured resource

Cybersecurity kit

Download a complete cybersecurity kit with blueprints, frameworks, checklists, policy templates, and UEM guidance.

DOWNLOAD

Where endpoint visibility fits in

Hexnode does not monitor Adobe Campaign Classic directly, ingest its application logs, or detect exploitation of this Adobe Campaign Classic vulnerability. Its role covers only the endpoints that administer or connect to Campaign Classic environments, not the application itself.

  • Before a patch is applied: Hexnode UEM can enforce patch and configuration compliance on managed Windows endpoints, as well as configuration and script-based compliance on Linux endpoints used to administer Campaign Classic.
  • During investigation: Hexnode XDR can investigate suspicious activity on managed endpoints, primarily Windows and macOS, and cross-reference endpoint telemetry with findings from Campaign Classic log review and identity security tools.

These capabilities complement, rather than replace, Adobe’s patch, application-level log analysis, and identity review. Hexnode does not patch Adobe Campaign Classic or provide server-side application monitoring.

FAQs

No. Adobe has already remediated its hosted instances; the advisory applies to fully on-premises deployments and the on-premises components of hybrid deployments.

No. Adobe has not confirmed exploitation in the wild, but a CVSS 10.0, unauthenticated, zero-interaction flaw warrants immediate patching, since public disclosure can accelerate exploit development.

Yes. Review integration credentials and service accounts connected to Campaign Classic, and confirm administrative endpoints are running current security updates, in addition to upgrading the application itself.

Conclusion

This Adobe Campaign Classic vulnerability’s CVSS 10 score, lack of authentication requirement, and lack of user interaction leave little margin for delay on exposed, on-premises deployments. Organizations should confirm their deployment model, apply build 9398, and review logs and credentials for signs of activity that predates the fix.

Closing the vulnerability is the first step, not the last. Verifying that administrative endpoints are current, credentials are clean, and no unexplained activity occurred before the patch will help increase confidence in containment.

Share

Sophia Hart

A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions—without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable—politely.