Adobe Campaign Classic Hit by Perfect 10 CVSS Flaw Allowing Full System Takeover

Adobe Campaign Classic Hit by Perfect 10 CVSS Flaw Allowing Full System Takeover

Adobe has released critical security updates for its Campaign Classic enterprise marketing automation platform to address two serious vulnerabilities. The most severe issue, tracked as CVE-2026-48449, carries the maximum possible severity score of 10.0 and stems from an incorrect authorization flaw. This vulnerability could allow attackers to execute arbitrary code with the privileges of the current user without requiring any interaction from the victim, making it particularly dangerous for enterprise environments.

The security update also patches a second high-severity vulnerability, CVE-2026-48448, which has a CVSS score of 8.6. This flaw is caused by a SQL injection vulnerability that could enable attackers to read arbitrary files from the affected system. Both vulnerabilities have been fixed in Campaign Classic version 7.4.3 build 9398 for Windows and Linux platforms. Adobe has stated that it is not currently aware of either vulnerability being actively exploited in the wild, but the severity of these issues underscores the importance of prompt patching.

In addition to the Campaign Classic updates, Adobe has released patches for Adobe Bridge that address eight critical vulnerabilities. These flaws could allow attackers to escalate privileges and execute arbitrary code on affected systems. The vulnerabilities were discovered and reported by security researchers Kieran and yjdfy. Adobe is urging all users of these products to install the latest updates immediately to protect their systems from potential exploitation. Given the critical nature of these vulnerabilities, particularly the maximum-severity flaw in Campaign Classic, organizations should prioritize deploying these patches as part of their regular security maintenance.

Stay secure — stay Wavasec. 🔐