Bulletin ID
Security update available for Adobe Campaign Classic | APSB26-120
|
|
Date Published |
Priority |
|
APSB26-120 |
August 3, 2026 |
1 |
Summary
Adobe has released a security update for Adobe Campaign Classic. This update addresses critical vulnerabilities that could result in arbitrary code execution.
Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates.
Affected versions
| Product | Affected version | Platform |
|---|---|---|
| Adobe Campaign Classic |
ACC v7: 7.4.3 build 9398 and earlier | Windows, Linux |
Solution
Adobe categorizes these updates with the following priority rating and recommends users update their installation to the newest version:
| Product | Updated version | Platform | Priority rating | Availability |
|---|---|---|---|---|
| Adobe Campaign Classic |
ACC v7 7.4.3 build 9399 | Windows, Linux | 1 |
This security bulletin applies only to fully on-premise deployments of Adobe Campaign Classic and to the on-premise components of hybrid deployments. Adobe-hosted instances have already been remediated and require no customer action.
Vulnerability Details
| Vulnerability Category | Vulnerability Impact | Severity | CVSS base score | CVSS vector | CVE Number |
Server-Side Request Forgery (SSRF) (CWE-918) |
Arbitrary code execution |
Critical |
10.0 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
CVE-2026-48331 |
Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) |
Arbitrary code execution |
Critical |
10.0 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
CVE-2026-48323 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) |
Arbitrary code execution |
Critical |
10.0 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
CVE-2026-48330 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) |
Arbitrary code execution |
Critical |
9.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
CVE-2026-48326 |
Incorrect Authorization (CWE-863) |
Privilege escalation |
Critical |
9.8 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
CVE-2026-48333 |
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95) |
Arbitrary code execution |
Critical |
9.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
CVE-2026-48317 |
Violation of Secure Design Principles (CWE-657) |
Security feature bypass |
Critical |
7.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
CVE-2026-48399 |