Protect.Computer
NEWS

Adobe Patches CVSS 10.0 Bug in Campaign Classic Platform

· 1 min read · Got hacked Malicious byte
Adobe Patches CVSS 10.0 Bug in Campaign Classic Platform

Adobe has released an urgent security update for Campaign Classic (ACC), its enterprise marketing-automation platform, to address two serious vulnerabilities — the more critical of which carries the maximum possible CVSS score of 10.0. The flaw, tracked as CVE-2026-48449, stems from an incorrect authorization check and allows an attacker to execute arbitrary code on a vulnerable server without any action from a logged-in user. A second bug, CVE-2026-48448 (CVSS 8.6), is a SQL-injection vulnerability that could let an attacker read arbitrary files from the server’s file system. Adobe says it has no evidence either vulnerability has been exploited in the wild, but a CVSS 10 score — the ceiling — means the theoretical risk of remote exploitation without user interaction is as severe as vulnerabilities get.

Both flaws are patched in Campaign Classic v7, build 7.4.3 (build 9398), available for both Windows and Linux. In the same update cycle, Adobe separately patched eight critical-rated vulnerabilities in Adobe Bridge that could lead to privilege escalation and arbitrary code execution; those are fixed in Adobe Bridge 14.1.4. Security researcher Kieran (“kaiksi”) and researcher “yjdfy” are credited with discovering the Bridge flaws.

How to check if you’re affected

Affected versions are Campaign Classic v7 builds earlier than 7.4.3 (build 9398). Organizations running ACC v7 on Windows or Linux should verify their installed build number in the About dialog and apply Adobe Security Bulletin APSB26-114 immediately. Hosted Campaign Classic instances managed by Adobe itself may receive the patch automatically, but self-hosted and hybrid deployments require a manual upgrade.

Sources

Related reading