>samit_hota
Back to security news
SN-2026-266CriticalResolved

Adobe Patches Maximum-Severity CVSS 10.0 Zero-Click Flaw in Campaign Classic

Samit Hota·
CVE ID
CVE-2026-48449
Affected Products / Orgs
Adobe Campaign Classic, Adobe Bridge
#news#vulnerability-disclosure#adobe

A maximum-severity Adobe Campaign Classic vulnerability allows remote attackers to execute arbitrary code without requiring any user interaction. Tracked as CVE-2026-48449, the security flaw carries a maximum CVSS score of 10.0 and stems from an incorrect authorization failure in Adobe’s enterprise marketing automation platform. Adobe issued security updates to address the issue alongside a second high-severity SQL injection vulnerability in the same platform and eight critical-rated bugs affecting Adobe Bridge.

Dissecting the Adobe Campaign Classic Vulnerabilities

The flagship issue, CVE-2026-48449, is classified as an incorrect authorization flaw. In enterprise application security, incorrect authorization occurs when an application fails to properly validate whether a requesting user or session possesses the required permissions to execute a specific administrative or system action. Because this flaw requires zero user interaction, an attacker who can reach the application’s interface or API services can issue crafted requests that trigger code execution in the security context of the running service account.

Enterprise marketing platforms like Adobe Campaign Classic (ACC) hold significant strategic value for threat actors. These servers orchestrate high-volume customer communications, connect to internal customer relationship management (CRM) databases, and store sensitive customer information and transactional records. Achieving arbitrary code execution on an ACC server provides an attacker with a powerful footholds inside corporate environments, enabling lateral movement, data exfiltration, or access to linked messaging services.

Alongside CVE-2026-48449, Adobe fixed CVE-2026-48448, a high-severity flaw with a CVSS score of 8.6. This bug is caused by a SQL injection vulnerability that allows remote actors to execute arbitrary file reads across the underlying server file system. SQL injection occurs when user-supplied input is improperly sanitized before being processed by backend database queries. In an enterprise web application, arbitrary file read capabilities allow attackers to extract sensitive application secrets, database credentials, configuration files, and cryptographic keys, which can be leveraged to escalate privileges or move across internal systems.

Both Campaign Classic vulnerabilities affect both Windows and Linux server environments. Adobe confirmed that both flaws are resolved in ACC v7: 7.4.3 build 9398.

Critical Arbitrary Code Execution Patches for Adobe Bridge

In the same release cycle, Adobe issued patches for eight critical-rated vulnerabilities in Adobe Bridge, a popular digital asset management tool used by creative teams to organize and preview media files. These vulnerabilities could allow attackers to execute arbitrary code or escalate local system privileges:

  • CVE-2026-48395 (CVSS 8.6) and CVE-2026-48391 (CVSS 8.2): Untrusted search path vulnerabilities that lead to arbitrary code execution. Search path vulnerabilities typically occur when an application searches for external dependencies or dynamic libraries in insecure or user-writable directories, allowing local attackers to drop malicious binaries that execution routines load automatically.
  • CVE-2026-48396 (CVSS 8.6): An incorrect authorization vulnerability resulting in arbitrary code execution.
  • CVE-2026-48390 (CVSS 8.6): An incorrect authorization vulnerability leading to local privilege escalation.
  • CVE-2026-48374 (CVSS 7.8): A path traversal vulnerability enabling code execution. Path traversal occurs when input validation fails to filter directory navigation characters, permitting unauthorized access to files outside designated working directories.
  • CVE-2026-48392, CVE-2026-48393, and CVE-2026-48394 (CVSS 7.8 each): Out-of-bounds write memory corruption flaws that lead to arbitrary code execution when processing malicious files.

Adobe credited security researcher Kieran (“kaiksi”) with discovering CVE-2026-48390, CVE-2026-48391, CVE-2026-48395, CVE-2026-48396, and CVE-2026-48374. Researcher “yjdfy” was credited for discovering the three out-of-bounds write flaws (CVE-2026-48392, CVE-2026-48393, and CVE-2026-48394).

Current Exposure and Patching Requirements

In its official security advisory, Adobe stated that it is not aware of any active exploitation in the wild targeting these vulnerabilities prior to disclosure. However, maximum-severity zero-click bugs in publicly facing or enterprise-integrated platforms represent immediate targets for automated scanning and exploit development.

Administrators running enterprise deployments of Adobe Campaign Classic should update their instances to ACC v7: 7.4.3 build 9398 or later on both Windows and Linux hosts immediately. Security teams should also verify that Campaign Classic administrative interfaces are isolated behind secure firewalls or VPN connections to reduce exposed attack surfaces while patching is completed. Users of Adobe Bridge should apply the latest software updates through the Adobe Creative Cloud desktop application.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call