CVE-2026-48449

CVSS 10.0 · CRITICAL
EPSS p42
Lower risk — in the top 58% least-likely-to-be-exploited CVEs.
No patch reference
No patch/mitigation in references

Published 7/30/2026 · updated 7/30/2026 · CWE-863

Share
Get asset-aware triage

Summary

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

CVSS 10.0CRITICAL

10.0 / 10
  • AV: Network
  • AC: Low complexity
  • PR: No privileges
  • UI: No user interaction
  • S: Scope changed
  • C: Confidentiality: High
  • I: Integrity: High
  • A: Availability: High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

EPSS exploitation probability

0.5%

Percentile p42 Lower risk — in the top 58% least-likely-to-be-exploited CVEs.

Timeline

  1. Jul 30, 2026 · Disclosed / published in NVD
  2. Jul 30, 2026 · Intel last updated

Intel sources

Which upstream feeds returned data for this CVE, and when they were last fetched.

  • NVD· 1 day ago
  • CVE.org· 1 day ago
  • FIRST EPSS· 1 day ago
  • CISA KEV· no data
  • OSV· 1 day ago

References

Unlock the full report

See how CVE-2026-48449 hits your stack.

Free public data ends here. Sign in to correlate this CVE against your SBOM and assets, get an AI-grounded exploit chain, generate a ModSecurity virtual patch, and share findings with your team.

  • · Asset-aware CVSS & priority
  • · Grounded AI analysis (A–D graded)
  • · Auto-generated WAF / IPS rules
  • · Jira, SIEM, Slack, Teams delivery

No credit card · 100 free enrichments · analyst-grade citations.