CVE-2026-48449 – Adobe Campaign Classic

CVSS 10 CRITICAL Critical - Same Day Deployment

“When authorization breaks down, attackers don't need an invitation.”

This patch addresses CVE-2026-48449, an Incorrect Authorization vulnerability (CWE-863) affecting Adobe Campaign Classic (ACC). The CVSS score is 10.0, which is Critical severity. No verified real-world exploitation has been reported.

The vulnerability could allow an attacker to achieve arbitrary code execution in the context of the current user by exploiting improper authorization controls. Exploitation does not require user interaction, increasing the potential impact on affected systems. Although the vulnerability is not identified as Remote Code Execution (RCE), it has Elevation of Privilege (EoP) characteristics because successful exploitation enables unauthorized execution within the user’s security context. Adobe has released an update to correct the authorization flaw and organizations should prioritize deployment due to the Critical severity.

Key Details

Affected Product
Adobe Campaign
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-863
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.