CVE-2026-48333

Adobe · Campaign Classic

Adobe Campaign Classic is vulnerable to an Incorrect Authorization flaw allowing unauthenticated attackers to perform privilege escalation.

Executive summary

An unauthenticated privilege escalation vulnerability in Adobe Campaign Classic poses a critical risk to system integrity and administrative control.

Vulnerability

This vulnerability involves an Incorrect Authorization flaw (CWE-863) within the application, which allows an unauthenticated remote attacker to gain elevated privileges through a network-based attack vector.

Business impact

The ability for an unauthenticated attacker to escalate privileges represents a total compromise of the application security model. With a CVSS score of 9.8, this flaw could lead to unauthorized access to sensitive customer data, administrative actions, and potential lateral movement within the corporate network.

Remediation

Immediate Action: Update Adobe Campaign Classic to version 7.4.3 build 9399 or later immediately.

Proactive Monitoring: Review system access logs for unusual administrative logins or unauthorized modifications to user permission sets.

Compensating Controls: Deploy Web Application Firewall rules to block unauthorized requests attempting to interact with sensitive authorization endpoints.

Exploitation status

Public Exploit Available: unknown

Analyst recommendation

Given the critical CVSS severity and the lack of authentication required for exploitation, organizations must prioritize patching this vulnerability. Failure to remediate could result in full administrative takeover of the affected Campaign Classic instance.