← Back to blog

Adobe Campaign Classic Flaw Exposes Enterprises to Critical RCE Risk

A newly patched CVSS 10.0 vulnerability in Adobe Campaign Classic could allow attackers to execute arbitrary code without user interaction. Organizations using the platform should apply updates immediately.

TL;DR

  • Adobe released patches for CVE-2026-48449, a critical auth bypass flaw in Campaign Classic
  • The vulnerability scores 10.0 on CVSS, the highest severity rating
  • Attackers can exploit it for remote code execution without requiring user interaction
  • Enterprises using ACC must update to the latest version to prevent potential compromise
  • No active exploitation has been reported, but immediate patching is advised

Adobe has addressed a critical security vulnerability in its Campaign Classic marketing automation platform that could allow unauthenticated remote attackers to execute arbitrary code. The flaw, assigned CVE-2026-48449, received the maximum CVSS severity score of 10.0, indicating the highest level of risk.

The vulnerability stems from an incorrect authorization implementation that could be exploited without any user interaction. This makes it particularly dangerous for enterprises relying on Campaign Classic for customer engagement and marketing operations, as attackers could potentially gain full control of affected systems.

Vulnerability Details

  • CVE-2026-48449 is an improper authorization flaw in Adobe Campaign Classic
  • The vulnerability allows remote code execution with maximum privileges
  • No user interaction or authentication is required for exploitation
  • CVSS base score is 10.0 (Critical) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Impact and Recommendations

  • Organizations using Adobe Campaign Classic are at risk of complete system compromise
  • Attackers could access sensitive customer data and marketing infrastructure
  • Adobe has released security updates addressing the vulnerability in affected versions
  • Enterprises should immediately verify their ACC version and apply patches
  • Consider network segmentation and monitoring for suspicious activity during patch deployment

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

Adobe Campaign Classic Flaw Exposes Enterprises to Critical RCE Risk — Agent Breach Blog | Agent Breach