← back

CVE-2026-48449

CRITICAL · 10.0 EPSS 0.5%
hype MIXED · 52 hack

Real critical vuln but no KEV, PoC, or confirmed patch availability; early-stage awareness.

What: Incorrect Authorization vulnerability in Adobe Campaign Classic enabling arbitrary code execution without user interaction; CVSS 10.0 critical severity.

Why it matters: Published yesterday with perfect CVSS score and no-interaction RCE capability across scope. However, not yet KEV-listed and no public PoC or confirmed in-the-wild exploitation reported. Social chatter reflects severity but lacks concrete exploitation signal. Adobe patch (build 9398) referenced but not yet verified as official/available.

Where it's seen: High-engagement posts on security social media highlighting CVSS 10 and RCE potential; aggregator sites republishing; calls for immediate patching. No researcher PoC drops, no defender triage reports, no advisory confirmation visible yet.

RISK: CRITICAL — CVSS 10, no user interaction, scope change, authorization bypass enabling RCE.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 7/31/2026, 3:53:08 AM

Description

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

CVSS 3.1 breakdown

Exploitability 3.9 · Impact 6.0
vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack vector
Network
Complexity
Low
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Weaknesses