CVE-2026-48449

Adobe Security Bulletin APSB26-114 — Campaign

criticalEPSS 1 %

Beschreibung

Adobe Campaign Classic (ACC) ist von einer Fehlkonfiguration der Autorisierung betroffen, die zur willkürlichen Codeausführung im Kontext des aktuellen Benutzers führen könnte. Die Ausnutzung dieses Problems erfordert keine Interaktion mit dem Benutzer. Der Geltungsbereich wurde geändert.

Metriken

Severity
critical
kein öffentlicher PoC bekannt
10.0
Quelle: cna-v3
59.4 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
1.0 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-07-30 02:48 UTC
CWE-863

Weakness-Klassen (CWE)

  • CWE-863Class

    Incorrect Authorization

    The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-08-28 00:18 UTC· psirt@adobe.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/48xxx/CVE-2026-48449.json">CVE-2026-48449</a>
    • Reference: https://helpx.adobe.com/security/products/campaign/apsb26-114.html
    • Reference: https://helpx.adobe.com/security/products/campaign/apsb26-114.html
    • Reference Type: https://helpx.adobe.com/security/products/campaign/apsb26-114.html Types: Vendor Advisory
  2. Initial Analysis2026-08-05 14:54 UTC· nvd@nist.gov
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    • CPE Configuration: AND OR *cpe:2.3:a:adobe:campaign:7.4.3:9394:*:*:classic:*:*:* *cpe:2.3:a:adobe:campaign:7.4.3:9396:*:*:classic:*:*:* *cpe:2.3:a:adobe:campaign:7.4.3:9397:*:*:classic:*:*:* *cpe:2.3:a:adobe:campaign:7.4.3:9398:*:*:classic:*:*:* *cpe:2.3:a:adobe:campaign:*:*:*:*:classic:*:*:* versions up to (including) 7.4.2 OR cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    • Reference Type: Adobe Systems Incorporated: https://helpx.adobe.com/security/products/campaign/apsb26-114.html Types: Vendor Advisory
  3. CVE Modified2026-08-03 19:16 UTC· psirt@adobe.com
    • Affected: Adobe Campaign ClassicAdobe Campaign Classic
  4. CVE Modified2026-07-30 14:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-48449","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
  5. New CVE Received2026-07-30 03:16 UTC· psirt@adobe.com
    • Affected: Adobe Campaign Classic
    • Description: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    • CWE: CWE-863

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • adobe

    campaign7.4.2

  • adobe

    campaign

Quellen & Referenzen

Verknüpfte CVEs

Verknüpfte Empfehlungen

IDCVE-2026-48449