Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2981 articles · 185103 vulns · 37/41 feeds (7d)
← Back to list
10.0
CVE-2026-48449PATCHED
adobe · campaign

Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)

Description

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Affected Products

VendorProductVersions
adobecampaign0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
linuxlinux_kernelcve_cpe95%
microsoftwindowscve_cpe95%

References

  • https://helpx.adobe.com/security/products/campaign/apsb26-114.html(vendor-advisory)

Related News (3 articles)

Tier D
Heise Security5d ago
Kritische Schadcode-Sicherheitslücke bedroht Adobe Campaign Classic
→ No new info (linked only)
Tier D
The Hacker News7d ago
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
→ No new info (linked only)
Tier C
VulDB10d ago
CVE-2026-48449 | Adobe Campaign Classic improper authorization
→ No new info (linked only)
CVSS 3.110.0 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
7.4.3 build 9398
CWECWE-863
PublishedJul 30, 2026
Trending Score32
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-48448
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Trending: 25
CRITICALCVE-2026-48333
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
Trending: 25
CRITICALCVE-2026-48330
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Trending: 25
CRITICALCVE-2026-48323
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
Trending: 25
CRITICALCVE-2026-48331
Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)
Trending: 25

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 30, 2026
Discovered by ZDM
Jul 30, 2026
Patch Available
Aug 3, 2026