Adobe Security Bulletin

Security update available for Adobe Campaign Classic | APSB26-120

Bulletin ID

Date Published

Priority

APSB26-120

August 3, 2026

1

Summary

Adobe has released a security update for Adobe Campaign Classic. This update addresses critical vulnerabilities  that could result in arbitrary code execution.

Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates.  

Affected versions

Product Affected version Platform
Adobe Campaign Classic
ACC v7: 7.4.3 build 9398 and earlier Windows, Linux

Solution

Adobe categorizes these updates with the following priority rating and recommends users update their installation to the newest version:

Product Updated version Platform Priority rating Availability
Adobe Campaign Classic
ACC v7 7.4.3 build 9399 Windows, Linux 1

Release Notes

Pastaba

This security bulletin applies only to fully on-premise deployments of Adobe Campaign Classic and to the on-premise components of hybrid deployments. Adobe-hosted instances have already been remediated and require no customer action.

Vulnerability Details

Vulnerability Category Vulnerability Impact Severity CVSS base score CVSS vector CVE Number

Server-Side Request Forgery (SSRF) (CWE-918)

Arbitrary code execution

Critical

10.0

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVE-2026-48331

Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)

Arbitrary code execution

Critical

10.0

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 

CVE-2026-48323

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)

Arbitrary code execution

Critical

10.0

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVE-2026-48330

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)

Arbitrary code execution

Critical

9.9

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CVE-2026-48326

Incorrect Authorization (CWE-863)

Privilege escalation

Critical

9.8

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2026-48333

Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95)

Arbitrary code execution

Critical

9.6

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

CVE-2026-48317

Violation of Secure Design Principles (CWE-657)

Security feature bypass

Critical

7.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVE-2026-48399

 

Pastaba
Effective August 11, 2026, Adobe may assign a single CVE identifier to internally discovered vulnerabilities with the same severity rating and CWE category when a release includes systemic fixes.

Gaukite pagalbą greičiau ir lengviau

Naujas vartotojas?