CVE-2026-48399
Adobe · Adobe Campaign Classic
Adobe Campaign Classic is susceptible to a violation of secure design principles, which may result in a security feature bypass.
Executive summary
A high-severity security feature bypass vulnerability in Adobe Campaign Classic could allow unauthorized access to protected system functions.
Vulnerability
The software suffers from a violation of secure design principles (CWE-657), enabling an unauthenticated attacker to bypass established security features within the application.
Business impact
This vulnerability allows attackers to circumvent security controls, potentially leading to unauthorized access to sensitive campaign data or administrative functions. With a CVSS score of 7.5, the risk to confidentiality and the integrity of marketing operations is substantial.
Remediation
Immediate Action: Upgrade Adobe Campaign Classic to build 9399 or later as specified in the vendor security advisory.
Proactive Monitoring: Review application access logs for anomalous activity or unexpected authentication bypass patterns during the period prior to patching.
Compensating Controls: Implement strict network access controls and ensure that the Adobe Campaign instance is not exposed to the public internet where possible.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations utilizing Adobe Campaign Classic should treat this update with high urgency. Applying the patch to build 9399 is necessary to restore the intended security posture of the platform and prevent unauthorized feature access.