Skip to main content
CybersecurityVulnerability Management

Adobe Patches CVSS 10.0 Flaw in Campaign Classic

Empty marketing automation control room with computer screen and scattered papers.

CVE-2026-48449 carries a severity score of 10.0 on the CVSS scoring system.

CVE-2026-48449: an incorrect-authorization flaw in Adobe Campaign Classic that can run code without user interaction

Adobe has released updates to address a maximum-severity vulnerability in Campaign Classic (ACC), its enterprise marketing automation product. Tracked as CVE-2026-48449 and rated CVSS 10.0, the flaw has been described as an incorrect-authorization issue that "could result in arbitrary code execution in the context of the current user without requiring any user interaction." The wording in Adobe’s advisory emphasizes that successful exploitation would run code with the privileges of the account context in which the ACC process executes.

Related ACC issue, affected build and platforms

The company also fixed a separate high-severity weakness in Campaign Classic, CVE-2026-48448 (CVSS 8.6), which stems from SQL injection and "could pave the way for arbitrary file reads." Both shortcomings have been addressed in the same maintenance release: ACC v7: 7.4.3 build 9398 for Windows and Linux. Adobe said it is not aware of any of the flaws being exploited in the wild.

Adobe Bridge: eight critical-rated fixes and their technical profiles

  • CVE-2026-48395 (CVSS 8.6) — an untrusted search path vulnerability that leads to arbitrary code execution
  • CVE-2026-48396 (CVSS 8.6) — an incorrect authorization vulnerability that leads to arbitrary code execution
  • CVE-2026-48390 (CVSS 8.6) — an incorrect authorization vulnerability that leads to privilege escalation
  • CVE-2026-48391 (CVSS 8.2) — an untrusted search path vulnerability that leads to arbitrary code execution
  • CVE-2026-48374 (CVSS 7.8) — a path traversal vulnerability that leads to arbitrary code execution
  • CVE-2026-48392 (CVSS 7.8) — an out-of-bounds write vulnerability that leads to arbitrary code execution
  • CVE-2026-48393 (CVSS 7.8) — an out-of-bounds write vulnerability that leads to arbitrary code execution
  • CVE-2026-48394 (CVSS 7.8) — an out-of-bounds write vulnerability that leads to arbitrary code execution

Adobe credited security researcher Kieran ("kaiksi") with reporting CVE-2026-48390, CVE-2026-48391, CVE-2026-48395, CVE-2026-48396, and CVE-2026-48374, and researcher "yjdfy" for CVE-2026-48392, CVE-2026-48393, and CVE-2026-48394. The vendor said the updates remediate those critical-rated flaws in Adobe Bridge.

What this means for technologists, affected enterprises, and end users

  • Technologists and security teams: apply the ACC v7: 7.4.3 build 9398 updates for Windows and Linux and the Adobe Bridge updates as dispatched; Adobe’s advisory explicitly recommends applying the latest updates for optimal protection.
  • Affected enterprises and procurement leaders: ensure that Campaign Classic deployments and any Adobe Bridge installations are inventoried and brought to the patched versions, and coordinate rollouts to minimize operational disruption while addressing maximum- and high-severity flaws.
  • End users: although Adobe stated it is not aware of active exploitation, users and administrators should accept and deploy the vendor updates to mitigate risks that include remote arbitrary code execution and arbitrary file-system reads.

Adobe advisory and next step

Adobe framed the release as a grouped response to several high-risk defects: "This update addresses critical vulnerabilities that could result in arbitrary code execution and arbitrary file system read," the advisory states. The company also noted it is not aware of these flaws being exploited in the wild, leaving patch deployment as the immediate protective step the advisory recommends.

Original story