Return to Threats

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

thehackernews.com 2026-08-01 SaaS AI risk Critical

What Happened

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in

Why It Matters

The article reports that Adobe Campaign Classic on-premise v7 build 7.4.3.9397 and earlier suffers from CVE-2026-48449, an Incorrect Authorization (CWE-863) vulnerability rated CVSS 10.0 that enables arbitrary remote code execution over the network without privileges or user interaction.[7][4] Adobe states the flaw affects only on-premise and hybrid deployments, with hosted instances already patched, and urges immediate upgrades to build 7.4.3.9398.[7] From a RealGround perspective, any AI or data pipelines integrated with Adobe Campaign Classic (for customer data, personalization models, or marketing automation logic) could be fully compromised if an attacker exploits this RCE, enabling model tampering, data exfiltration, or insertion of malicious workflows into AI-driven campaigns. Organizations should treat ACC as a critical component in their AI supply chain, maintain an SBOM and dependency mapping for marketing/AI systems, and implement rapid patching and hardening for on-premise ACC instances to prevent downstream AI system compromise.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to SaaS AI risk. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/08/adobe-campaign-classic-cvss-100-flaw.html

Talk to AI CISO