Back to blog
CVEAdobeRCEtechnique

Adobe Campaign Classic CVE-2026-48449: a perfect 10.0 RCE in enterprise marketing

Published on 2026-08-015 min readCleanIssue

> In short: CVE-2026-48449 is a maximum-severity incorrect authorization flaw in Adobe Campaign Classic (ACC), scored at CVSS 10.0 — the perfect score. It allows arbitrary code execution in the context of the current user, without any user interaction. A companion flaw, CVE-2026-48448 (SQL injection, CVSS 8.6), enables arbitrary file reads. Both fixed in ACC v7 build 9398. Not exploited at disclosure.

Why this matters to you

Adobe Campaign Classic runs the marketing automation backend for a large share of enterprise organizations — the same enterprises that buy your SaaS. If a client uses ACC to send payroll notifications, onboarding emails, or customer communications, a compromise there gives the attacker a trusted channel straight into your users' inboxes.

A CVSS 10.0 is the maximum: network-reachable, low complexity, no privileges required, no user interaction, full impact on confidentiality, integrity, and availability. When a 10.0 drops, the operational rule is simple: patch before you do anything else today.

The two flaws

CVE-2026-48449 (CVSS 10.0): Incorrect authorization that results in arbitrary code execution. No user interaction required. An attacker who can reach the ACC instance over the network can execute code with the privileges of the application process.

CVE-2026-48448 (CVSS 8.6): SQL injection that enables arbitrary file reads. An attacker can read sensitive files from the server's filesystem — configuration files, credentials, database connection strings.

Together, the chain is: file read (steal config and credentials) → code execution (compromise the server). Adobe says neither flaw is being exploited in the wild as of the advisory.

What to do

  • Upgrade to ACC v7 build 9398 (or later) on every Campaign Classic instance, including staging and development. The window between disclosure and exploitation for a CVSS 10.0 is typically measured in days.
  • Take ACC off the internet if it doesn't need to be there. Marketing automation platforms are routinely exposed for partner integration — they shouldn't be. Reverse-proxy behind an authenticating gateway.
  • Audit for compromise if the instance was exposed: unexpected scheduled jobs, new admin accounts, modified delivery templates (a common persistence vector in Campaign — the attacker modifies a recurring campaign to exfiltrate data).
  • Rotate credentials stored in ACC: database connection strings, SMTP credentials, API integrations. CVE-2026-48448's file-read capability means any credential in a config file may have been accessed.
  • The enterprise marketing pattern

    Adobe Campaign Classic joins a pattern we see across enterprise marketing/CRM platforms: they hold trusted communication channels (email, SMS, push), they're exposed for integration, and they have complex permission models that produce authorization flaws. A compromised ACC instance can send phishing emails from your client's legitimate domain, modify delivery content, and exfiltrate subscriber data. For your SaaS vendor security questionnaire: ask whether clients running ACC are patched and whether the instance is internet-exposed.

    Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.

    Sources

    Written by CleanIssue
    Reviewed on 2026-08-01

    Related services

    If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.

    Need an external review of your HR SaaS?

    Share your product, stack, and client context. We will come back with the right review scope.

    Discuss your audit