


Perceptive Security
SOC/SIEM Consultancy

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current…
Published:
30 July 2026 at 00:00:00
Alert date:
30 July 2026 at 17:06:28
Source:
nvd.nist.gov
Enterprise Applications, Zero-Day Vulnerabilities, Identity & Access
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability tracked as CVE-2026-48449. The flaw can lead to arbitrary code execution in the context of the current user. Notably, exploitation does not require user interaction, lowering the barrier for attackers. The vulnerability also involves a scope change, meaning the impact can extend beyond the vulnerable component. Adobe has published a security advisory (APSB26-114) addressing this issue. The vulnerability is currently awaiting full analysis on NVD. Given the no-user-interaction requirement and potential for arbitrary code execution, this is considered a high-severity issue. Organizations using Adobe Campaign Classic should review the Adobe advisory and apply patches promptly.
Technical details
Mitigation steps:
Affected products:
Adobe Campaign Classic (ACC)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-48449
https://helpx.adobe.com/security/products/campaign/apsb26-114.html
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
