Adobe has closed a vulnerability in its marketing automation platform Campaign Classic that is rated with the highest possible CVSS score.
The vulnerability, tracked as CVE-2026-48449, stems from an incorrect authorization check in Adobe Campaign Classic, or ACC for short. It allowed arbitrary code to be executed in the context of the currently logged-in user, without an attacker needing any interaction from the victim or having to log in themselves beforehand. Alongside this flaw, Adobe closed a second vulnerability, rated high with a CVSS score of 8.6, which is based on an SQL injection and would have allowed arbitrary files on the server to be read.
Adobe stated that it is not aware of any exploitation of the vulnerabilities so far. Both flaws are fixed in build 9398 of ACC v7.4.3 for Windows and Linux; only self-hosted, on-premises installations of the software are affected, not instances hosted by Adobe itself. Back in June, Adobe had already closed a different vulnerability in Campaign Classic, likewise based on incorrect authorization, and updated customers to build 9397 at the time. The now-disclosed flaw was only discovered afterward, so anyone who has installed only the June update remains vulnerable and must additionally update to build 9398.
Eight further critical flaws in Adobe Bridge
Separately, Adobe also released updates for its file management software Adobe Bridge, closing a total of eight vulnerabilities rated as critical. These could allow attackers to escalate privileges or execute arbitrary code and are based, among other things, on untrusted search paths, incorrect authorization checks, path traversal vulnerabilities, and several out-of-bounds memory access errors. The associated CVSS scores range from 7.8 to 8.6. Adobe credited the security researchers going by the names kaiksi and yjdfy for discovering and reporting the Bridge vulnerabilities. Adobe advises users of both products to install the current updates promptly.
(red)