CVE-2026-48449
Adobe Security Bulletin APSB26-114 — Campaign
Beschreibung
Adobe Campaign Classic (ACC) ist von einer Fehlkonfiguration der Autorisierung betroffen, die zur willkürlichen Codeausführung im Kontext des aktuellen Benutzers führen könnte. Die Ausnutzung dieses Problems erfordert keine Interaktion mit dem Benutzer. Der Geltungsbereich wurde geändert.
Metriken
Weakness-Klassen (CWE)
CWE-863Class
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- CVE Modified2026-08-28 00:18 UTC· psirt@adobe.com
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/48xxx/CVE-2026-48449.json">CVE-2026-48449</a>
- Reference: https://helpx.adobe.com/security/products/campaign/apsb26-114.html
- Reference: https://helpx.adobe.com/security/products/campaign/apsb26-114.html
- Reference Type: https://helpx.adobe.com/security/products/campaign/apsb26-114.html Types: Vendor Advisory
- Initial Analysis2026-08-05 14:54 UTC· nvd@nist.gov
- CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CPE Configuration: AND OR *cpe:2.3:a:adobe:campaign:7.4.3:9394:*:*:classic:*:*:* *cpe:2.3:a:adobe:campaign:7.4.3:9396:*:*:classic:*:*:* *cpe:2.3:a:adobe:campaign:7.4.3:9397:*:*:classic:*:*:* *cpe:2.3:a:adobe:campaign:7.4.3:9398:*:*:classic:*:*:* *cpe:2.3:a:adobe:campaign:*:*:*:*:classic:*:*:* versions up to (including) 7.4.2 OR cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
- Reference Type: Adobe Systems Incorporated: https://helpx.adobe.com/security/products/campaign/apsb26-114.html Types: Vendor Advisory
- CVE Modified2026-08-03 19:16 UTC· psirt@adobe.com
- Affected: Adobe Campaign Classic → Adobe Campaign Classic
- CVE Modified2026-07-30 14:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-48449","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
- New CVE Received2026-07-30 03:16 UTC· psirt@adobe.com
- Affected: Adobe Campaign Classic
- Description: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
- CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- CWE: CWE-863
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
adobe
campaign7.4.2
adobe
campaign