CVE-2026-48449

Adobe · Campaign Classic

An incorrect authorization vulnerability in Adobe Campaign Classic allows unauthenticated attackers to achieve arbitrary code execution.

Executive summary

Adobe Campaign Classic is affected by a critical authorization vulnerability that enables unauthenticated remote code execution.

Vulnerability

The software suffers from an incorrect authorization flaw that permits an unauthenticated attacker to execute arbitrary code with the privileges of the application user.

Business impact

With a CVSS score of 10.0, this vulnerability represents the highest level of risk to the organization. Successful exploitation allows an attacker to gain full control over the application server, leading to potential data exfiltration, service disruption, and total system compromise.

Remediation

Immediate Action: Update Adobe Campaign Classic to build 9398 or later to resolve the authorization flaw.

Proactive Monitoring: Monitor server logs for suspicious process execution or unexpected outbound network connections from the application server.

Compensating Controls: Implement strict network segmentation and egress filtering to limit the impact if the server is compromised.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the critical severity and the potential for complete system takeover, administrators should prioritize updating Adobe Campaign Classic to build 9398 immediately. Ensure that all staging and production instances are accounted for during the patch deployment process.