Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-48396 | Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. NVD description · AI analysis pending | 8.6 group max | <1% |
| — | ||
| CVE-2026-48449 +1 in the same advisory: …48448 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. NVD description · AI analysis pending | 9.8 group max | <1% |
| — |
Full article382 words · extracted from securityaffairs.com · click to collapse

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction.
Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute arbitrary code in the context of the current user without requiring any user interaction.
“Adobe has released a security update for Adobe Campaign Classic. This update addresses critical vulnerabilities that could result in arbitrary code execution and arbitrary file system read.” reads the advisory. “Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates.”
Organizations using Adobe Campaign Classic should apply the available security updates as soon as possible to reduce the risk of exploitation.
Adobe also fixed CVE-2026-48448 (CVSS score 8.6), a high-severity SQL injection flaw that could allow arbitrary file reads.
Both vulnerabilities are patched in Adobe Campaign Classic v7.4.3 build 9398 for Windows and Linux.
Adobe also released updates for Adobe Bridge, fixing eight critical vulnerabilities that could allow attackers to execute arbitrary code or escalate privileges. The flaws include incorrect authorization, untrusted search path, path traversal, and out-of-bounds write vulnerabilities, with CVSS scores ranging from 7.8 to 8.6.
Below is the list of the flaws:
| Vulnerability Category | Vulnerability Impact | Severity | CVSS base score | CVSS vector | CVE Number |
| Untrusted Search Path (CWE-426) | Arbitrary code execution | Critical | 8.6 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H | CVE-2026-48395 |
| Incorrect Authorization (CWE-863) | Arbitrary code execution | Critical | 8.6 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H | CVE-2026-48396 |
| Incorrect Authorization (CWE-863) | Privilege escalation | Critical | 8.2 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N | CVE-2026-48390 |
| Untrusted Search Path (CWE-426) | Arbitrary code execution | Critical | 8.2 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H | CVE-2026-48391 |
| Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) (CWE-22) | Arbitrary code execution | Critical | 7.8 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | CVE-2026-48374 |
| Out-of-bounds Write (CWE-787) | Arbitrary code execution | Critical | 7.8 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | CVE-2026-48392 |
| Out-of-bounds Write (CWE-787) | Arbitrary code execution | Critical | 7.8 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | CVE-2026-48393 |
| Out-of-bounds Write (CWE-787) | Arbitrary code execution | Critical | 7.8 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | CVE-2026-48394 |
Researcher Kieran (kaiksi) disclosed the flaws CVE-2026-48390, CVE-2026-48391, CVE-2026-48395, CVE-2026-48396, and CVE-2026-48374, while the researcher yjdfy reported the vulnerabilities CVE-2026-48392, CVE-2026-48393, and CVE-2026-48394.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Campaign Classic)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/196429/security/adobe-fixed-a-maximum-severity-vulnerability-flaw-in-campaign-classic.html