ctipilot.ch

Adobe Campaign Classic — Incorrect Authorization (CWE-863) giving unauthenticated arbitrary code execution; CVSS 3.1 10.0, on-premise and hybrid on-premise components only, fixed in ACC v7 7.4.3 build 9398 (APSB26-114)

cve · CVE-2026-48449 single-source

Coverage timeline
1
first 2026-08-02 → last 2026-08-02
Peak priority
high
1 high
Sources cited
1
1 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
1
see Related entities below
ATT&CK techniques
1
pinned v19.1 · see below

Hunting pivots

ATT&CK techniques
Affected products
Adobe Campaign Classic

ATT&CK techniques

1 technique observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-02/adobe-campaign-classic-apsb26-114-cvss10-unauth-rce · ATT&CK page ↗

Story timeline

  1. 2026-08-02CVE-2026-48449 — Adobe Campaign Classic: an authorization flaw gives unauthenticated arbitrary code execution (CVSS 10.0), on-premise and hybrid deployments only
    trending-vulnerabilitiesAdobe ships a priority-1 fix for a CVSS 10.0 unauthenticated code-execution flaw in Campaign Classic — only self-hosted and hybrid installs need action

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • helpx.adobe.com1 (100%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Adobe Campaign Classic — Incorrect Authorization (CWE-863) giving unauthenticated arbitrary code execution; CVSS 3.1 10.0, on-premise and hybrid on-premise components only, fixed in ACC v7 7.4.3 build 9398 (APSB26-114) (1)

2026-08-02 · view entry permalink →

CVE-2026-48449 — Adobe Campaign Classic: an authorization flaw gives unauthenticated arbitrary code execution (CVSS 10.0), on-premise and hybrid deployments only

This is a recovery published by the 2026-08-02 weekly quality audit: the bulletin landed inside the audit window and no entry covered it.

The number that decides the timeline here is not the 10.0 but the vector. Adobe's own table gives CVE-2026-48449 as CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H — network reachable, low complexity, no privileges required, no user interaction, scope changed — against an Incorrect Authorization weakness (CWE-863) whose impact Adobe records as arbitrary code execution (Adobe, 2026-07-29). An authorization flaw reached without credentials on an internet-facing application is the shape that does not wait for the quarterly window, and Adobe agrees to the extent its own scale allows: it assigns priority rating 1, its most urgent. The sibling CVE-2026-48448 is a SQL injection at CVSS 8.6 with the same PR:N/UI:N prefix, impact recorded as arbitrary file-system read.

The scoping note is the part most likely to be misread in an estate inventory. Adobe states that "This security bulletin applies only to fully on-premise deployments of Adobe Campaign Classic and to the on-premise components of hybrid deployments" — Adobe-hosted instances were remediated by Adobe and need no customer action. A hybrid deployment is the trap: the hosted half is already fixed while the on-premise half is not, so an organisation whose asset register records Campaign as a SaaS product will conclude wrongly that it has nothing to do. Adobe also states it "is not aware of any exploits in the wild for any of the issues addressed in these updates", which is the correct hedge to carry — this entry is about mechanics and exposure, not about observed attacks.

What makes Campaign Classic worth the attention beyond the score is what it holds and what it touches. It is a campaign-execution platform: marketing and citizen-communication databases, subscriber lists, personal contact data, and an outbound sending capability tied to the organisation's own domain. Code execution on that host is simultaneously a personal-data exposure and a trusted-sender takeover, and public-sector bodies using it for citizen notifications inherit both.

Triage: there is no published exploitation and no proof-of-concept, so there is no attack pattern to match yet. What can be checked now is retrospective and cheap: on an ACC host that was internet-reachable while below build 9398, review the application and web-server logs for requests reaching authenticated functionality without a preceding successful authentication event, and for process creation under the ACC service account with a web-server parent — those are the generic manifestations an authorization bypass reaching code execution would produce, and their absence over the exposure window is a meaningful negative on a host with no other exposure.

This security bulletin applies only to fully on-premise deployments of Adobe Campaign Classic and to the on-premise components of hybrid deployments

Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates.

Adobe 2026-07-29
vulnerability02 Aug 13:50Zsingle-sourceOpen finding ↗
Sources: Adobe