Adobe Patches Perfect-10 Flaw in Campaign Classic That Lets Attackers Run Code Remotely

A permission check gone wrong in Adobe's marketing automation platform could hand attackers full control, with no user interaction needed.

ThreatVectr Newsdesk· 4 min read
Photoreal, news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Share

Key points

  • Adobe has patched a maximum-severity flaw in Campaign Classic, tracked as CVE-2026-48449, which scores a perfect 10.0 on the industry severity scale.
  • The bug is an authorisation failure that lets an unauthenticated attacker run their own code on the server without any user having to click anything.
  • Campaign Classic is Adobe's enterprise email and marketing automation tool, used by large brands to send customer campaigns and hold customer contact data.
  • Adobe's security bulletin urges administrators to apply the fix immediately.

Adobe has issued an emergency fix for a flaw in Campaign Classic, its enterprise marketing automation platform, that carries the highest possible severity rating.

The bug is tracked as CVE-2026-48449. It scores 10.0 out of 10.0 on the Common Vulnerability Scoring System, the industry's standard severity scale. A 10.0 is rare. It means the flaw is easy to exploit, needs no login, and hands the attacker something close to full control.

What is Campaign Classic and who uses it?

Campaign Classic, often shortened to ACC, is the software large companies use to plan and send marketing emails, texts and push notifications to customers. It typically sits on servers that hold customer contact lists, campaign histories and personal details used for targeting.

That context matters. A server running Campaign Classic is not a dusty back-office box. It usually holds live customer data and connects to the wider corporate network.

What does the flaw actually do?

Adobe describes the issue as "incorrect authorization" leading to arbitrary code execution. In plain English: the software fails to properly check whether the person making a request is allowed to make it, and an attacker can abuse that gap to run their own commands on the server.

According to Adobe's advisory, first flagged by The Hacker News, no user interaction is required. Nobody at the target company has to click a link, open a file or approve anything. An attacker who can reach the Campaign Classic instance over the network can trigger it directly.

That combination, no login and no click, is what pushes the score to 10.0.

How bad is a CVSS 10.0 in practice?

Very bad. A 10.0 is the ceiling of the scoring system, and Adobe rarely issues one. For comparison, most serious flaws land in the 7 to 9 range and still require some condition to be met, such as a valid account or a user opening a document.

Here the attacker needs neither.

Detail Value
CVE ID CVE-2026-48449
CVSS score 10.0 (maximum)
Affected product Adobe Campaign Classic (ACC)
Flaw type Incorrect authorisation, remote code execution
User interaction None required
Authentication None required

Is it being exploited?

Adobe has not, at the time of writing, said the flaw is being actively exploited. Its bulletin does not mention public exploit code either. That can change quickly. Perfect-10 bugs in widely deployed enterprise software tend to attract reverse-engineering attention within days of a patch dropping, because the fix itself often reveals where to look.

What should affected organisations do?

Patch now. Adobe's advisory lists the fixed versions of Campaign Classic, and administrators should apply them without waiting for a maintenance window.

Until the patch is deployed, restrict network access to Campaign Classic servers so they cannot be reached from the public internet or from untrusted parts of the corporate network. Check web server and application logs for unusual POST requests, unexpected process launches, or new administrative accounts created around the disclosure window.

If your organisation is a Campaign Classic customer and personal data was accessible on that server, breach-notification duties may follow depending on jurisdiction. In the UK that would fall to the Information Commissioner's Office; in the US, state attorneys general and the Federal Trade Commission; in Australia, the Office of the Australian Information Commissioner. Preserve logs before you patch, in case an investigation later needs them.

For ordinary customers of brands that use Campaign Classic, there is nothing to do yet. If a company confirms customer data was taken, watch for a notification letter and treat any unexpected marketing email claiming to be from that brand with suspicion.

© 2026 Threat Vectr