CVE-2026-48449
CRITICAL · 10.0 EPSS 0.5%Real critical vuln but no KEV, PoC, or confirmed patch availability; early-stage awareness.
What: Incorrect Authorization vulnerability in Adobe Campaign Classic enabling arbitrary code execution without user interaction; CVSS 10.0 critical severity.
Why it matters: Published yesterday with perfect CVSS score and no-interaction RCE capability across scope. However, not yet KEV-listed and no public PoC or confirmed in-the-wild exploitation reported. Social chatter reflects severity but lacks concrete exploitation signal. Adobe patch (build 9398) referenced but not yet verified as official/available.
Where it's seen: High-engagement posts on security social media highlighting CVSS 10 and RCE potential; aggregator sites republishing; calls for immediate patching. No researcher PoC drops, no defender triage reports, no advisory confirmation visible yet.
RISK: CRITICAL — CVSS 10, no user interaction, scope change, authorization bypass enabling RCE.
Description
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H- Attack vector
- Network
- Complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Changed
- Confidentiality
- High
- Integrity
- High
- Availability
- High