2026-08-02 · view entry permalink →
CVE-2026-48449 — Adobe Campaign Classic: an authorization flaw gives unauthenticated arbitrary code execution (CVSS 10.0), on-premise and hybrid deployments only
This is a recovery published by the 2026-08-02 weekly quality audit: the bulletin landed inside the audit window and no entry covered it.
The number that decides the timeline here is not the 10.0 but the vector. Adobe's own table gives CVE-2026-48449 as CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H — network reachable, low complexity, no privileges required, no user interaction, scope changed — against an Incorrect Authorization weakness (CWE-863) whose impact Adobe records as arbitrary code execution (Adobe, 2026-07-29). An authorization flaw reached without credentials on an internet-facing application is the shape that does not wait for the quarterly window, and Adobe agrees to the extent its own scale allows: it assigns priority rating 1, its most urgent. The sibling CVE-2026-48448 is a SQL injection at CVSS 8.6 with the same PR:N/UI:N prefix, impact recorded as arbitrary file-system read.
The scoping note is the part most likely to be misread in an estate inventory. Adobe states that "This security bulletin applies only to fully on-premise deployments of Adobe Campaign Classic and to the on-premise components of hybrid deployments" — Adobe-hosted instances were remediated by Adobe and need no customer action. A hybrid deployment is the trap: the hosted half is already fixed while the on-premise half is not, so an organisation whose asset register records Campaign as a SaaS product will conclude wrongly that it has nothing to do. Adobe also states it "is not aware of any exploits in the wild for any of the issues addressed in these updates", which is the correct hedge to carry — this entry is about mechanics and exposure, not about observed attacks.
What makes Campaign Classic worth the attention beyond the score is what it holds and what it touches. It is a campaign-execution platform: marketing and citizen-communication databases, subscriber lists, personal contact data, and an outbound sending capability tied to the organisation's own domain. Code execution on that host is simultaneously a personal-data exposure and a trusted-sender takeover, and public-sector bodies using it for citizen notifications inherit both.
Triage: there is no published exploitation and no proof-of-concept, so there is no attack pattern to match yet. What can be checked now is retrospective and cheap: on an ACC host that was internet-reachable while below build 9398, review the application and web-server logs for requests reaching authenticated functionality without a preceding successful authentication event, and for process creation under the ACC service account with a web-server parent — those are the generic manifestations an authorization bypass reaching code execution would produce, and their absence over the exposure window is a meaningful negative on a host with no other exposure.
This security bulletin applies only to fully on-premise deployments of Adobe Campaign Classic and to the on-premise components of hybrid deployments
Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates.