Incorrect Authorization Vulnerability in Adobe Campaign Classic
CVE-2026-48286

10CRITICAL

Key Information:

Vendor

Adobe

Vendor
CVE Published:
30 June 2026

What is CVE-2026-48286?

CVE-2026-48286 is a significant Incorrect Authorization vulnerability affecting Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier. Adobe Campaign Classic is a marketing automation tool designed to help businesses manage their marketing campaigns, customer data, and related processes effectively. This vulnerability enables attackers to potentially execute arbitrary code within the context of the current user, which poses a serious security risk. Notably, exploitation of this vulnerability demands no user interaction, meaning attackers could launch attacks more discreetly. This could lead to unauthorized access and manipulation of sensitive data, compromising the integrity and confidentiality of an organization's marketing operations.

Potential impact of CVE-2026-48286

  1. Arbitrary Code Execution: The vulnerability allows attackers to execute arbitrary code in the context of the user, which could lead to full system compromise, enabling them to manipulate or extract sensitive data without the user's consent.

  2. Unauthorized Access and Data Breach: By exploiting this vulnerability, malicious actors could gain unauthorized access to customer databases and marketing materials, potentially leading to leaks of personal information and sensitive business data.

  3. Operational Disruption: The exploitation of this vulnerability could disrupt marketing operations, affecting campaign delivery and overall business processes, as attackers could manipulate or halt marketing workflows, leading to financial losses and reputational damage.

Affected Version(s)

Adobe Campaign Classic (ACC) 0 <= 7.4.3 build 9396

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.