Affected Systems
Adobe Campaign Classic (ACC) v7 versions prior to 7.4.3 build 9398 on Windows and Linux. The vulnerability affects the enterprise marketing automation platform used for customer campaign management.
Exploitation Status
No active exploitation detected. Adobe states it is not aware of any in-the-wild exploitation of CVE-2026-48449 or CVE-2026-48448 at time of advisory publication.
Business Impact
Maximum severity (CVSS 10.0) incorrect authorization flaw enables arbitrary code execution in the context of the current user without requiring user interaction. A secondary SQL injection vulnerability (CVE-2026-48448, CVSS 8.6) allows arbitrary file system reads. Campaign Classic is an enterprise platform handling customer data and marketing operations, making compromise potentially high-impact for data confidentiality and business continuity.
Urgency
🔴 Immediate
Recommended Actions
- Immediately upgrade Adobe Campaign Classic v7 to version 7.4.3 build 9398 or later on all Windows and Linux instances
- Audit Campaign Classic access logs for unauthorized code execution attempts or unusual SQL queries prior to patching
- Review user authorization configurations in Campaign Classic to identify any privilege misconfigurations that could be exploited
- If immediate patching is not feasible, implement network segmentation to restrict Campaign Classic access to trusted internal networks only
- Monitor Campaign Classic application logs and system process execution for anomalous activity post-patching
