Adobe fixes CVSS 10 Campaign Classic bug that needs no user click

Adobe patches a CVSS 10 Campaign Classic flaw that allows code execution with no user interaction.

CSBadmin
2 Min Read

Adobe has shipped emergency fixes for a maximum-severity flaw in Campaign Classic, its enterprise marketing automation platform, that allows arbitrary code execution without any user interaction.

The vulnerability, tracked as CVE-2026-48449, carries a perfect 10.0 CVSS score. Adobe describes it as incorrect authorization that could result in arbitrary code execution in the context of the current user, requiring no action from the victim.

The same patch round covers a second issue, CVE-2026-48448 (CVSS 8.6), a SQL injection weakness that could allow arbitrary file reads. Both are fixed in Campaign Classic v7.4.3 build 9398 on Windows and Linux.

Adobe said it is not aware of either vulnerability being exploited in the wild, but the severity and the zero-interaction requirement make patching urgent for the marketing teams that run the platform.

In a separate advisory, Adobe also addressed eight critical-rated flaws in Adobe Bridge that could lead to privilege escalation and arbitrary code execution. The batch includes CVE-2026-48390, CVE-2026-48391, CVE-2026-48395, and CVE-2026-48396, all rated 8.6, plus four other issues scored 7.8 or 8.2, including path traversal and out-of-bounds writes.

Security researcher Kieran, known as kaiksi, was credited with discovering five of the Bridge flaws, while researcher yjdfy reported the remaining three. Users are advised to apply the latest updates as soon as possible.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.