VDB
CVE-2026-48449
CVE-2026-48449
PUBLISHED
CVSS 10 CRITICAL
CVE-2026-48449 is a critical vulnerability with CVSS score of 10.0 that stems from incorrect authorization and it has a changed scope. CVE-2026-48448 is a high vulnerability with CVSS score of 8.6 that stems from improper neutralization of special elements used in an SQL command (SQL injection) and it has a changed scope. An attacker can exploit it to disclose sensitive memory and access files on the files system without permission.
EPSS 0.54% · 42.6th percentile
Risk Scores
CVSS 3.1
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
0.54%
42.6th percentile
Timeline
- Jul 30, 2026 EPSS Score
- Jul 30, 2026 CVE Published
- Aug 5, 2026 CVE Updated
- Aug 7, 2026 EPSS Score
References
- https://ccb.belgium.be/advisories/warning-1-critical-and-1-high-vulnerability-adobe-campaign-classic-can-lead-arbitrary advisory
- https://helpx.adobe.com/security/products/campaign/apsb26-114.html vendor
- https://nvd.nist.gov/vuln/detail/CVE-2026-48448 technical
- https://nvd.nist.gov/vuln/detail/CVE-2026-48449 technical