Adobe CVSS 10.0 Flaw

Overview

Adobe has released urgent security updates for Campaign Classic (ACC), its enterprise marketing automation platform, to fix a maximum‑severity flaw that could allow attackers to execute arbitrary code without any user interaction. The vulnerability, tracked as CVE‑2026‑48449, carries a CVSS score of 10.0, the highest possible rating.

Critical Vulnerabilities

  1. CVE‑2026‑48449 (CVSS 10.0)
    • Incorrect authorization flaw.
    • Enables arbitrary code execution in the context of the current user.
    • Requires no user interaction.
  2. CVE‑2026‑48448 (CVSS 8.6)
    • SQL injection vulnerability.
    • Could allow arbitrary file reads.

Both flaws are patched in ACC v7: 7.4.3 build 9398 for Windows and Linux.

Additional Adobe Bridge Flaws

Adobe also patched eight critical vulnerabilities in Adobe Bridge, including:

  • Untrusted search path flaws leading to code execution.
  • Incorrect authorization flaws enabling privilege escalation.
  • Path traversal and out‑of‑bounds write flaws allowing arbitrary code execution.

Key CVEs include:

  • CVE‑2026‑48395 – Untrusted search path (CVSS 8.6).
  • CVE‑2026‑48396 – Incorrect authorization (CVSS 8.6).
  • CVE‑2026‑48390 – Privilege escalation (CVSS 8.6).
  • CVE‑2026‑48374 – Path traversal (CVSS 7.8).

Adobe credited researchers Kieran (“kaiksi”) and yjdfy for reporting these flaws.

Why This Matters

  • No exploitation reported yet, but the severity means attackers could weaponize these flaws quickly.
  • Enterprise risk: Campaign Classic is widely used in marketing automation, making it a high‑value target.
  • Bridge vulnerabilities: Affect creative workflows, potentially exposing sensitive design and project files.

Defensive Guidance

  • Update immediately: Install ACC v7.4.3 build 9398 or later.
  • Patch Adobe Bridge to the latest release.
  • Monitor for suspicious activity: Look for unusual file reads or unauthorized process execution.
  • Restrict privileges to minimize impact if exploitation occurs.

Expert in the Cloud Insight

This disclosure highlights how authorization flaws and SQL injection remain critical risks even in enterprise platforms. With a CVSS 10.0 rating, CVE‑2026‑48449 is a reminder that patch velocity matters as much as patch availability. Organizations should treat these updates as urgent, not optional, and integrate continuous monitoring to detect exploitation attempts before they escalate.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.