Adobe Campaign Classic Critical Incorrect Authorization Flaw Enables Unauthenticated Remote Code Execution (CVE-2026-48449) Paired With SQL Injection Memory/File Disclosure (CVE-2026-48448) — Threadlinqs Intelligence
As of 2026-08-09, Adobe Campaign Classic Critical Incorrect Authorization Flaw Enables Unauthenticated Remote Code Execution (CVE-2026-48449) Paired With SQL Injection Memory/File Disclosure (CVE-2026-48448) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 39 indicators of compromise.
Threat ID: TL-2026-1790 · Severity: CRITICAL · CVSS: 10 · Status: ACTIVE · Category: VULNERABILITY
Updated: 2026-08-09 · 3 updates · revalidated 3× · latest source
Adobe Campaign Classic (ACC) v7 contains an Incorrect Authorization vulnerability (CVE-2026-48449, CVSS 10.0/CWE-863) enabling unauthenticated arbitrary code execution, and a related SQL Injection
On July 30, 2026, Adobe published security bulletin APSB26-114 for Adobe Campaign Classic (ACC) v7, disclosing two vulnerabilities affecting build 9397 and earlier: CVE-2026-48449, a maximum-severity (CVSS 3.1 base score 10.0, vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) Incorrect Authorization flaw (CWE-863) that allows an unauthenticated, network-based attacker to achieve arbitrary code execution in the context of the current user without any interaction from a victim; and CVE-2026-48448, a high-severity (CVSS 3.1 base score 8.6, vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N) SQL Injection flaw (CWE-89) that lets the same class of unauthenticated attacker read arbitrary regions of application memory and access the underlying file system through injected SQL. Both flaws carry a Changed scope (S:C) in their CVSS vectors, indicating the vulnerable ACC component can affect resources beyond its own security scope once exploited. Adobe fixed both issues in ACC v7 7.4.3 build 9398; instances hosted by Adobe were already remediated and require no customer action, but fully on-premise deployments and the on-premise leg of hybrid deployments remain exposed until the customer applies the update.
The Dutch national CERT, NCSC-NL, republished the Adobe findings on July 31, 2026 as CSAF advisory NCSC-2026-0273 ("Kwetsbaarheden verholpen in Adobe Campaign Classic") to alert its constituency, citing APSB26-114 as the authoritative source and reiterating that exploitation of either CVE requires no privileges and no user interaction. Neither CVE-2026-48449 nor CVE-2026-48448 appears in the CISA Known Exploited Vulnerabilities (KEV) catalog as of this writing, and no public proof-of-concept exploit code, exploitation tooling, or in-the-wild attack activity has been reported for either vulnerability by Adobe, NCSC-NL, or open security reporting.
This is not an isolated event for ACC's authorization layer. One month earlier, Adobe shipped APSB26-69 (~June 30, 2026) fixing CVE-2026-48286, another maximum-severity (CVSS 10.0) Incorrect Authorization vulnerability in the same product affecting build 9396 and earlier, patched in build 9397 — the exact predecessor build range to the flaws documented here. The two disclosures one build-cycle apart establish a recurring pattern of authorization-layer weaknesses in ACC's on-premise component that defenders and Adobe itself should treat as a class-level risk, not a one-off bug. Adobe CSO Aanchal Gupta announced this cadence change on June 25, 2026 via the Adobe Security Blog, explicitly citing AI-accelerated vulnerability discovery — "frontier AI models and agentic analysis tooling now uncover flaws across large codebases far faster than traditional methods could" — as compressing the gap between disclosure and exploitation from days to hours; the new cadence (second and fourth Tuesday of each month) took effect July 14, 2026, meaning ACC administrators should expect a tighter, more frequent patch cycle going forward and should budget for Priority 1 (patch within ~72 hours) turnaround on future ACC bulletins. Notably, NVD's own CVE-2026-48449 and CVE-2026-48448 records show a published date of July 29, 2026 — one day ahead of the July 30 APSB26-114 bulletin text and public disclosure — with both records last-modified July 30, 2026 to align with the released bulletin; this is a coordinated-disclosure timing artifact, not evidence of independent pre-bulletin discovery.
Because CVE-2026-48449 grants code execution and CVE-2026-48448 grants memory/file-system read access on the same unauthenticated, network-reachable component, the two vulnerabilities are readily chainable: an attacker could use the SQL injection to enumerate configuration files, credentials, or session material before or after using the authorization bypass to execute arbitrary code, or use the authorization bypass alone to gain code execution directly. No evidence currently indicates this chaining has been observed in practice; the risk doc
Weaknesses (CWE)
CWE-863, CWE-89
Target sectors: marketingtechnology, retail, financialservices, mediaentertainment, telecoms, government administration
Target regions: Global
Update History
- 2026-08-09 — CVE-2026-48449: Adobe Campaign Classic Incorrect Authorization Leads to Unauthenticated RCE (CVSS 10.0): What changed Severity/exploitability/status unchanged (CRITICAL / THEORETICAL / ACTIVE). New development: Adobe shipped a follow-on bulletin APSB26-120 (2026-08-03, 5 days after this threat's APSB26-114) patching 7 more Campaign Classic fla
- 2026-08-04 — Adobe Campaign Classic v7 — Two Critical Vulnerabilities (CVE-2026-48449, CVE-2026-48448): What changed No change to severity (CRITICAL), exploitability (THEORETICAL), status (ACTIVE), CVSS (10.0), or attribution (LOW/Unknown) — the newer report confirms the same assessment rather than escalating it. New indicators (13) 13 new in
- 2026-08-01 — Adobe Patches Maximum-Severity CVE-2026-48449 (CVSS 10.0) in Campaign Classic — Unauthenticated Arbitrary Code Execution: What changed No change to severity (CRITICAL), exploitability (THEORETICAL), CVSS (10.0/8.6), status, or attribution. The newer report adds technical attack-surface detail (SOAP endpoint, exposed ports, service process/API names) not previo
Detections & IOCs
As of 2026-08-17, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 39 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-48449, CVE-2026-48448, CVE-2026-48303, CVE-2026-48331, CVE-2026-48323, CVE-2026-48330, CVE-2026-48326, CVE-2026-48333, CVE-2026-48317, T1595, T1588, T1190, T1059, T1505, T1136, T1068, T1070, T1027, T1552