All stories
criticalExploited VulnerabilitiesCVE-2026-48449

Attackers can execute arbitrary code via critical authorization flaw in Adobe Campaign Classic

🚨 An incorrect authorization flaw in Adobe Campaign Classic allows attackers to execute arbitrary code without any user interaction. This vulnerability carries a maximum CVSS score of 10.0. Patch your instances immediately to prevent unauthorized remote access.

Summary

Adobe has disclosed a critical security flaw in Adobe Campaign Classic (ACC) that permits an attacker to run code within the context of the current user. The vulnerability, identified as CVE-2026-48449, is classified as an incorrect authorization issue. Because the flaw allows for scope change, successful exploitation can impact the broader system beyond the initial access point.

The vulnerability is highly critical due to its ease of use; it does not require a user to click a link or perform any specific action to trigger the code execution. This makes it a high-priority target for remote attackers looking to gain a foothold in marketing automation environments.

Technical details

The core of the issue lies in how Adobe Campaign Classic handles authorization requests. An incorrect authorization mechanism allows an unauthenticated or low-privileged actor to bypass intended restrictions.

According to the technical advisory, the flaw results in arbitrary code execution. Because the vulnerability changes the scope of the impact, an attacker can move from a limited session to executing commands that affect the underlying system or broader application environment. The CVSS score of 10.0 reflects this total loss of confidentiality, integrity, and availability through a network-based attack vector.

Why this matters for defenders

Marketing automation platforms like Adobe Campaign Classic often hold sensitive customer data and integrate deeply with corporate email and database systems. An attacker gaining code execution capabilities on these servers could potentially access or manipulate large datasets or use the compromised instance to launch further attacks within the internal network.

The lack of required user interaction means that traditional defenses relying on user awareness-such as phishing training-will not mitigate this specific risk. Defenders must treat this as a direct remote exploitation threat that can be executed via the network.

Defender guidance

Immediate action is required to secure Adobe Campaign Classic environments. Organizations should prioritize the following steps:

  • Apply Security Updates: Review the official Adobe security advisory and apply all available patches for your specific version of Adobe Campaign Classic immediately.
  • �Verify Version Integrity: Confirm that your running instances are not on vulnerable versions by checking against the product list provided in the vendor's documentation.
  • Monitor System Logs: Watch for unusual process executions or unauthorized changes to system configurations originating from the ACC service account.

For more specific details regarding the vulnerability and available fixes, consult the official advisory: https://helpx.adobe.com/security/products/campaign/apsb26-114.html

Sources

  1. https://thehackernews.com/2026/08/adobe-campaign-classic-cvss-100-flaw.html
  2. https://helpx.adobe.com/security/products/campaign/apsb26-114.html
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -