Incorrect Authorization Vulnerability in Adobe Campaign Classic by Adobe
CVE-2026-48449

10CRITICAL

Key Information:

Vendor

Adobe

Vendor
CVE Published:
30 July 2026

Badges

📰 News Worthy

What is CVE-2026-48449?

Adobe Campaign Classic is susceptible to an Incorrect Authorization vulnerability, which may allow an attacker to execute arbitrary code within the context of the current user without the need for user interaction. This exposure could lead to significant security risks if exploited, making it critical for users to assess their systems and implement necessary security measures.

Affected Version(s)

Adobe Campaign Classic 0 <= 7.4.3 build 9397

Adobe Campaign Classic 0 <= 7.4.3 build 9397

Adobe Campaign Classic 7.4.3 build 9398

News Articles

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe patches CVE-2026-48449, a CVSS 10.0 Campaign Classic flaw that could allow code execution without user interaction, plus eight Bridge flaws.

3 days ago

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 📰

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

.