Critical Zero-Click Vulnerability in Adobe Campaign Classic Exposes Enterprise Systems to Remote Code Execution
Overview
CVE-2026-48286 represents an unprecedented risk with a CVSS 10.0 score, enabling unauthenticated attackers to execute arbitrary code remotely without user interaction. This flaw affects Adobe Campaign Classic, Linux kernel, and Windows systems, requiring immediate mitigation.
Technical Analysis
The vulnerability stems from insufficient authorization controls in Adobe Campaign Classic versions 7.4.3 build 9396 and earlier. Attackers can exploit this by sending maliciously crafted API requests to validate session tokens or trigger code execution paths, bypassing intended access restrictions. The flaw operates pre-authentication, eliminating the need for credentials or user engagement, and leverages a changed-scope vulnerability in privilege escalation logic.
Enterprise & DIB Impact
Defense Industrial Base (DIB) entities and enterprises utilizing Adobe Campaign Classic or vulnerable OS kernels face a critical exposure. A successful exploit could establish persistent access to email marketing platforms, CRM infrastructures, or enterprise servers, enabling data exfiltration, lateral movement, or ransomware deployment.
Recommended Actions
- Apply Adobe's latest security patch for Campaign Classic immediately
- disable unnecessary API endpoints via firewall rules
- monitor server logs for anomalous API requests
- enforce network segmentation for marketing/CRM systems
- and conduct privilege audit of API token validation mechanisms.
Need Help Assessing Your Exposure?
Axiom Cyber Research provides vulnerability assessment, red team operations, and security advisory services to the Defense Industrial Base and regulated sectors.
Schedule a ConsultationFull security advisory on 247alerts.net →