CVE-2026-48399

Adobe · Adobe Campaign Classic

Adobe Campaign Classic is susceptible to a violation of secure design principles, which may result in a security feature bypass.

Executive summary

A high-severity security feature bypass vulnerability in Adobe Campaign Classic could allow unauthorized access to protected system functions.

Vulnerability

The software suffers from a violation of secure design principles (CWE-657), enabling an unauthenticated attacker to bypass established security features within the application.

Business impact

This vulnerability allows attackers to circumvent security controls, potentially leading to unauthorized access to sensitive campaign data or administrative functions. With a CVSS score of 7.5, the risk to confidentiality and the integrity of marketing operations is substantial.

Remediation

Immediate Action: Upgrade Adobe Campaign Classic to build 9399 or later as specified in the vendor security advisory.

Proactive Monitoring: Review application access logs for anomalous activity or unexpected authentication bypass patterns during the period prior to patching.

Compensating Controls: Implement strict network access controls and ensure that the Adobe Campaign instance is not exposed to the public internet where possible.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations utilizing Adobe Campaign Classic should treat this update with high urgency. Applying the patch to build 9399 is necessary to restore the intended security posture of the platform and prevent unauthorized feature access.