hacker-news · Crawled Aug 1, 2026

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Read original article ↗

AI Summary

Adobe has patched a critical vulnerability, CVE-2026-48449, in its Campaign Classic (ACC) platform with a CVSS score of 10.0, stemming from incorrect authorization that allows arbitrary code execution without user interaction. Another high-severity flaw, CVE-2026-48448, involving SQL injection leading to arbitrary file reads, was also addressed. The updates apply to ACC v7: 7.4.3 build 9398 for Windows and Linux, with no known in-the-wild exploitation reported.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.