Adobe Campaign Classic Incorrect Authorization Enables RCE
Incorrect authorization flaw in Adobe Campaign Classic scores CVSS 10.0, enabling unauthenticated remote code execution without user interaction. Adobe has patched.
- Vendor
- Adobe
- Product
- Campaign Classic
- CVSS
- 10.0
- EPSS (exploit probability)
- 0.5%
- Status
- patched
- Published
Adobe Campaign Classic (ACC), Adobe’s enterprise marketing automation platform, contains a maximum-severity incorrect authorization vulnerability that allows an unauthenticated network attacker to execute arbitrary code without any user interaction.
The flaw is classified under incorrect authorization (CWE-285 / related class): software fails to verify that a requestor is entitled to access a resource or invoke an action. At CVSS 10.0, exploitation requires no privileges and no victim interaction — the attack surface is the network.
Adobe released security updates on August 1, 2026. Affected version ranges and the full Adobe security bulletin are available through Adobe’s PSIRT advisories. The NVD entry links to advisory details as they are published.
Exploitation status: No confirmed active exploitation reported at time of writing. CVE-2026-48449 is not listed in CISA’s Known Exploited Vulnerabilities catalog as of publication.
What to do: Apply the available Adobe security update immediately. Organizations using Campaign Classic through a managed service provider should confirm patch status with their provider rather than assuming it has been applied.
For full technical advisory details, see the NVD record and The Hacker News coverage.
