Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN805
_____________________________________________________________________

DATE                : 03/08/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Adobe Campaign Classic versions
                            prior to ACC v7: 7.4.3 build 9398.
 
=====================================================================
https://helpx.adobe.com/security/products/campaign/apsb26-114.html
_____________________________________________________________________


Adobe Security Bulletin
Last updated on Jul 30, 2026

Security update available for Adobe Campaign Classic | APSB26-114

Bulletin ID     Date Published      Priority

APSB26-114      July 29, 2026       1


Summary

Adobe has released a security update for Adobe Campaign Classic. This
update addresses critical vulnerabilities  that could result in
arbitrary code execution and arbitrary file system read.

Adobe is not aware of any exploits in the wild for any of the issues
addressed in these updates. 

 
Affected versions

Product 	Affected version 	Platform

Adobe Campaign Classic   ACC v7: 7.4.3 build 9397 and earlier
Windows, Linux


Solution

Adobe categorizes these updates with the following priority rating
and recommends users update their installation to the newest
version:

Product    Updated version    Platform    Priority rating
Availability

Adobe Campaign Classic  ACC v7: 7.4.3 build 9398
Windows, Linux   1 	Release Notes

Note

This security bulletin applies only to fully on-premise deployments
of Adobe Campaign Classic and to the on-premise components of
hybrid deployments. Adobe-hosted instances have already been
remediated and require no customer action.


Vulnerability Details

Vulnerability Category 	Vulnerability Impact 	Severity
CVSS base score 	CVSS vector 	CVE Number

Incorrect Authorization (CWE-863)
Arbitrary code execution
Critical      10.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE-2026-48449

Improper Neutralization of Special Elements used in an
SQL Command ('SQL Injection') (CWE-89)
Arbitrary file system read
Critical       8.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CVE-2026-48448

Note
Effective August 11, 2026, Adobe may assign a single CVE
identifier to internally discovered vulnerabilities with
the same severity rating and CWE category when a release
includes systemic fixes.


=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




