Threat Intelligence • CVE-2026-48449

Critical Adobe Campaign Classic Authorization Flaw

Adobe has released a Priority 1 update for an incorrect authorization vulnerability that may allow arbitrary code execution without authentication or user interaction.

Trends4You Editorial

Executive summary

What is confirmed

Adobe bulletin APSB26-114 identifies CVE-2026-48449 as a critical Incorrect Authorization vulnerability in Adobe Campaign Classic v7. Adobe assigns a CVSS 3.1 base score of 10.0 and states that successful exploitation could result in arbitrary code execution.

Scope matters

The bulletin applies to fully on-premises Adobe Campaign Classic deployments and the on-premises components of hybrid deployments. Adobe-hosted instances have already been remediated and require no customer action.

AffectedAdobe Campaign Classic v7, version 7.4.3 build 9397 and earlier, on Windows and Linux.
Updated versionAdobe Campaign Classic v7, version 7.4.3 build 9398.
Attack conditionsNetwork-accessible, low complexity, no privileges and no user interaction according to Adobe's published CVSS vector.
Observed exploitationAdobe stated it was not aware of exploitation in the wild when the bulletin was updated on 30 July 2026.
NVD statusAwaiting NVD enrichment at the time of publication; the vendor assessment is currently the substantive source.

Recommended response

Actions for administrators

1

Confirm deployment responsibility

Determine whether the environment is Adobe-hosted, fully on-premises or hybrid. Confirm which team or supplier owns the on-premises components.

2

Inventory versions

Identify every affected instance and supporting node. Do not assume the primary application record represents the complete deployment.

3

Apply Adobe's update

Prioritise build 9398 using an emergency change path proportionate to the service's exposure and criticality. Follow Adobe's release notes and preserve rollback readiness.

4

Reduce exposure while change is pending

Restrict network access to required administrative and application paths. Review internet exposure, reverse-proxy controls and unnecessary connectivity.

5

Review available evidence

Examine application, operating-system, proxy and security telemetry for unusual access or execution. Absence of an alert does not prove absence of compromise.

6

Verify and document

Confirm the updated build on every in-scope component, record any exception and monitor Adobe and NVD for revised guidance.

RACF-CC context

Why this is more than a patching task

This advisory connects to Domain 3 through exposure restriction, Domain 4 through inventory and verified remediation, Domain 6 through evidence review and Domain 8 through emergency change and exception governance.

Primary sources

Follow the live advisories

Threat information changes. Recheck the vendor bulletin before making production decisions.

Voluntary support

Found this useful? Support Trends4You

Trends4You's practical guides, RACF-CC resources and downloadable tools are provided free of charge. If they've helped you or your organisation, you can support the time and hosting that keeps them freely available.

Support is optional, handled securely by Stripe and does not provide additional access.