ctipilot.ch
← Back to the live brief
HIGHCVE-2026-48449 +1NATOA2vulnerability

CVE-2026-48449 — Adobe Campaign Classic: an authorization flaw gives unauthenticated arbitrary code execution (CVSS 10.0), on-premise and hybrid deployments only

discovered 2026-08-02 13:50 UTCrun 2026-08-02T1309Z-audit1 sourcesingle-source

This is a recovery published by the 2026-08-02 weekly quality audit: the bulletin landed inside the audit window and no entry covered it.

The number that decides the timeline here is not the 10.0 but the vector. Adobe's own table gives CVE-2026-48449 as CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H — network reachable, low complexity, no privileges required, no user interaction, scope changed — against an Incorrect Authorization weakness (CWE-863) whose impact Adobe records as arbitrary code execution (Adobe, 2026-07-29). An authorization flaw reached without credentials on an internet-facing application is the shape that does not wait for the quarterly window, and Adobe agrees to the extent its own scale allows: it assigns priority rating 1, its most urgent. The sibling CVE-2026-48448 is a SQL injection at CVSS 8.6 with the same PR:N/UI:N prefix, impact recorded as arbitrary file-system read.

The scoping note is the part most likely to be misread in an estate inventory. Adobe states that "This security bulletin applies only to fully on-premise deployments of Adobe Campaign Classic and to the on-premise components of hybrid deployments" — Adobe-hosted instances were remediated by Adobe and need no customer action. A hybrid deployment is the trap: the hosted half is already fixed while the on-premise half is not, so an organisation whose asset register records Campaign as a SaaS product will conclude wrongly that it has nothing to do. Adobe also states it "is not aware of any exploits in the wild for any of the issues addressed in these updates", which is the correct hedge to carry — this entry is about mechanics and exposure, not about observed attacks.

What makes Campaign Classic worth the attention beyond the score is what it holds and what it touches. It is a campaign-execution platform: marketing and citizen-communication databases, subscriber lists, personal contact data, and an outbound sending capability tied to the organisation's own domain. Code execution on that host is simultaneously a personal-data exposure and a trusted-sender takeover, and public-sector bodies using it for citizen notifications inherit both.

Triage: there is no published exploitation and no proof-of-concept, so there is no attack pattern to match yet. What can be checked now is retrospective and cheap: on an ACC host that was internet-reachable while below build 9398, review the application and web-server logs for requests reaching authenticated functionality without a preceding successful authentication event, and for process creation under the ACC service account with a web-server parent — those are the generic manifestations an authorization bypass reaching code execution would produce, and their absence over the exposure window is a meaningful negative on a host with no other exposure.

This security bulletin applies only to fully on-premise deployments of Adobe Campaign Classic and to the on-premise components of hybrid deployments

Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates.

Adobe 2026-07-29

Defender actions

  • Establish whether your Adobe Campaign Classic is Adobe-hosted or self-hosted before scheduling anything — Adobe states hosted instances are already remediated, so the work is confined to fully on-premise deployments and the on-premise components of hybrid ones; upgrade those to ACC v7 7.4.3 build 9398.

ATT&CK mapping

1 technique mapped from the cited reporting · MITRE ATT&CK v19.1

Initial Access TA0001
T1190Exploit Public-Facing Application

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.