Adobe Campaign Classic Critical Flaw (CVE-2026-48449) Allows Remote Code Execution
Adobe has addressed a critical vulnerability in Campaign Classic, identified as CVE-2026-48449, which carries a CVSS score of 10.0. This incorrect authorization flaw could enable arbitrary code execution in the context of the current user without requiring any user interaction. Another high-severity SQL injection flaw (CVE-2026-48448, CVSS 8.6) leading to arbitrary file reads was also resolved in the update.