Junglewise Threat Intelligence

CVE-2026-48449: Adobe Campaign Classic incorrect authorization remote code execution

CVE-2026-48449 · Severity: critical · CVSS 10 · Published 2026-07-30

Technologies: Adobe Campaign Classic. Vendors: Adobe.

Executive brief

Adobe Campaign Classic, a marketing automation platform used for managing cross-channel customer campaigns, is affected by a critical security flaw. This vulnerability allows an unauthorized attacker to remotely execute malicious code on the system without any user interaction. Successful exploitation could lead to a total compromise of the server, including the theft of sensitive customer data and disruption of marketing operations.

Technical details

Adobe Campaign Classic (ACC) contains an incorrect authorization vulnerability (CWE-863) that allows for remote code execution. The flaw is reachable over the network without authentication (AV:N/PR:N) and requires no user interaction (UI:N). Because the vulnerability results in a scope change (S:C), an attacker can potentially escape the application context to impact the underlying host system. The issue is resolved in Adobe Campaign Classic version 7.4.3 build 9398.

Affected products

  • Adobe Campaign Classic (ACC) <= 7.4.3 build 9397

Timeline

  • 2026-07-30: disclosed
  • 2026-07-30: advisory

References

Related threats