Adobe Campaign Classic Leaves On-Prem Deployments Exposed

Adobe Campaign Classic is one of those products where the control plane matters as much as the data. Here, a flaw in its authorization logic can let an attacker run code without user interaction, and a second flaw lets them issue unauthorized queries and reach files and memory through SQL injection. Adobe says the cloud version is already fixed, so the live exposure is in full on-premise and hybrid deployments. The advisory names CVE-2026-48449 and CVE-2026-48448, with the first rated CVSS 10.0 and the second 8.6, both patched in the 31-07-2026 release.

Part of the PlainSec briefing for 2026-07-31

Sources