{"id":2162,"date":"2026-08-01T07:26:00","date_gmt":"2026-08-01T07:26:00","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2162"},"modified":"2026-08-01T07:26:00","modified_gmt":"2026-08-01T07:26:00","slug":"adobe-campaign-classic-cvss-10-0-flaw-could-run-code-without-user-interaction","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2162","title":{"rendered":"Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Aug 01, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Enterprise Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgL4TR-PlW4MehiF4iAbWafpNUQrSuhhTuEZwgwba7Gi0mF-PfixGSlFmpsBm51WbJYfkA69ZYNjO2aWl8eE8tqdSPdJL7mvLOaYL9O6VWkfxw96YFF0Qxt1ggCurqVd2J2muf6SAjW0cCrt2UwnOO3rK76X-mBWHW1e8-2Mk6FERpS1yPrSVScImJ0TmKW\/s1700-e365\/adobe-flaw.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution.<\/p>\n<p>The vulnerability, tracked as <strong>CVE-2026-48449<\/strong>, carries a severity score of 10.0 on the CVSS scoring system.<\/p>\n<p>It has been described as a case of incorrect authorization that could result in arbitrary code execution in the context of the current user without requiring any user interaction.<\/p>\n<p>The update also resolves another high-severity flaw (<strong>CVE-2026-48448<\/strong>, CVSS score: 8.6) stemming from SQL injection that could pave the way for arbitrary file reads.<\/p>\n<p>\u00abThis update addresses critical vulnerabilities that could result in\u202farbitrary code execution and arbitrary file system read,\u00bb Adobe <a href=\"https:\/\/helpx.adobe.com\/security\/products\/campaign\/apsb26-114.html\" target=\"_blank\">said<\/a> in an advisory. The company noted that it&#8217;s not aware of any of the flaws being exploited in the wild.<\/p>\n<p>Both shortcomings have been addressed in ACC v7: 7.4.3 build 9398 for Windows and Linux.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/corelight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuvAqH13TTYyJD3aI-pJcYl54BoxQWMHc2aFwW2HbYUa5IKCjvHlzpzkFwXLTuV8aytky8kqLBgkoOtC8VQM5CGR0N5BXBl8RSXl-PYx_vIPbiLywiqXIvTPmm18cdEm_C0heVB-3U8zfG7K27RCAurtJ7OvxEyfQ0sVV_RRx1N4ZMWkqKgEBmkcDgjD6I\/s728-e100\/code-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Separately, Adobe has also shipped updates to <a href=\"https:\/\/helpx.adobe.com\/security\/products\/bridge\/apsb26-89.html\" target=\"_blank\">remediate eight critical-rated flaws<\/a> in Adobe Bridge that could lead to privilege escalation and arbitrary code execution &#8211;<\/p>\n<ul>\n<li><strong>CVE-2026-48395<\/strong> (CVSS score: 8.6) &#8211; An untrusted search path vulnerability that leads to arbitrary code execution<\/li>\n<li><strong>CVE-2026-48396<\/strong> (CVSS score: 8.6) &#8211; An incorrect authorization vulnerability that leads to arbitrary code execution<\/li>\n<li><strong>CVE-2026-48390<\/strong> (CVSS score: 8.6) &#8211; An incorrect authorization vulnerability that leads to privilege escalation<\/li>\n<li><strong>CVE-2026-48391<\/strong> (CVSS score: 8.2) &#8211; An untrusted search path vulnerability that leads to arbitrary code execution<\/li>\n<li><strong>CVE-2026-48374<\/strong> (CVSS score: 7.8) &#8211; A path traversal vulnerability that leads to arbitrary code execution<\/li>\n<li><strong>CVE-2026-48392<\/strong> (CVSS score: 7.8) &#8211; An out-of-bounds write vulnerability that leads to arbitrary code execution<\/li>\n<li><strong>CVE-2026-48393<\/strong> (CVSS score: 7.8) &#8211; An out-of-bounds write vulnerability that leads to arbitrary code execution<\/li>\n<li><strong>CVE-2026-48394<\/strong> (CVSS score: 7.8) &#8211; An out-of-bounds write vulnerability that leads to arbitrary code execution<\/li>\n<\/ul>\n<p>Adobe credited security researcher Kieran (\u00abkaiksi\u00bb) with discovering and reporting CVE-2026-48390, CVE-2026-48391, CVE-2026-48395, CVE-2026-48396, and CVE-2026-48374, and \u00abyjdfy\u00bb for CVE-2026-48392, CVE-2026-48393, and CVE-2026-48394.<\/p>\n<p>Users are advised to apply the latest updates for optimal protection.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Aug 01, 2026Vulnerability \/ Enterprise Security Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2163,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[1135,6,2287,10,497,70,2840,1774,1745],"class_list":["post-2162","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-adobe","tag-campaign","tag-classic","tag-code","tag-cvss","tag-flaw","tag-interaction","tag-run","tag-user"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2162","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2162"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2162\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2163"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2162"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2162"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2162"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}