AdobeCVE-2026-48449
Adobe Campaign Classic: improper authorization
Critical10.0CVE-2026-48449 · Published Jul 30, 2026 · updated Aug 28, 2026
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Adobe Campaign Classic Product | <= 7.4.3 build 9397 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-863
More Adobe advisories
All Adobe| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 31 | Adobe Premiere: out-of-bounds write | High7.8 | No fix yet |
| Jul 30 | Adobe Campaign Classic: SQL injection | High8.6 | No fix yet |
| Jul 28 | Adobe Bridge: improper authorization | High8.2 | No fix yet |
| Jul 28 | Adobe Bridge: untrusted search path | High8.2 | No fix yet |
| Jul 28 | Adobe Bridge: out-of-bounds write | High7.8 | No fix yet |
| Jul 28 | Adobe Bridge: out-of-bounds write | High7.8 | No fix yet |