Adobe Patches Critical CVSS 10.0 Remote Code Execution Flaw in Campaign Classic
A maximum-severity authorization vulnerability allows attackers to execute arbitrary code without user interaction.
Adobe has released an emergency security update to address a critical vulnerability in Adobe Campaign Classic (ACC) that allows for remote code execution. The flaw, tracked as CVE-2026-48449, carries a perfect CVSS 3.1 score of 10.0, the highest possible severity rating.
According to Adobe's security bulletin APSB26-114, published July 29, 2026, the vulnerability is classified as an incorrect authorization flaw (CWE-863). The bug enables an attacker to execute arbitrary code in the context of the current user. Critically, the exploit requires no special privileges and no user interaction to succeed, making it highly exploitable over a network.
The Scope of Impact
The vulnerability affects Adobe Campaign Classic v7, specifically build 7.4.3.9397 and all earlier versions. Because the flaw allows for full compromise of the system's confidentiality, integrity, and availability, it poses a severe risk to organizations utilizing the platform for enterprise marketing automation. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) confirms that the attack is network-reachable and requires low complexity to execute.
Why It Matters
A CVSS 10.0 rating indicates that the vulnerability is trivial to exploit remotely and can lead to total system takeover. For enterprises managing sensitive customer data within ACC, this flaw represents a significant risk of data exfiltration and unauthorized system control. The lack of required authentication means that any network-reachable instance of the affected software is potentially vulnerable to an external actor, bypassing standard security perimeters.
Next Steps for Administrators
Adobe recommends that all affected users upgrade to build 7.4.3.9398 immediately to resolve the issue. Administrators should verify their current build version and apply the patch to prevent potential exploitation of the authorization flaw. Given the severity of the vulnerability, immediate patching is the only reliable way to ensure the integrity of the marketing automation environment and protect against unauthorized remote access.