Description
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-08-11
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Campaign Classic is impacted by an incorrect authorization flaw that permits an attacker to execute arbitrary code on the system in the context of the current user. The weakness is classified as CWE-863, allowing privilege escalation without user interaction. If exploited, an attacker could run arbitrary commands, alter data, or compromise the integrity of the entire Campaign instance.

Affected Systems

Adobe Corporation – Adobe Campaign Classic. No specific version numbers are disclosed, so any installation of Adobe Campaign Classic is vulnerable until a patch that addresses this authorization issue is applied.

Risk and Exploitability

The CVSS score of 10 indicates maximum severity, while the EPSS score of less than 1% suggests a very low but non-zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote access via Web services or the administration interface where flawed permission checks can be bypassed, and the changed scope may grant full system control.

Generated by OpenCVE AI on August 12, 2026 at 21:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Campaign Classic security update that resolves the incorrect authorization flaw.
  • Restrict user permissions to the minimum required for their role, especially administrators who have elevated privileges.
  • Configure and monitor audit logs for unauthorized data access or command execution attempts that could indicate exploitation of this flaw.

Generated by OpenCVE AI on August 12, 2026 at 21:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe campaign
CPEs cpe:2.3:a:adobe:campaign:*:*:*:*:classic:*:*:*
Vendors & Products Adobe campaign

Thu, 13 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe campaign Classic
Vendors & Products Adobe
Adobe campaign Classic

Tue, 11 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Title Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Campaign Campaign Classic
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:34:06.284Z

Reserved: 2026-02-18T22:02:41.399Z

Link: CVE-2026-27302

cve-icon Vulnrichment

Updated: 2026-08-13T14:15:47.211Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T18:17:25.603

Modified: 2026-08-28T00:17:13.797

Link: CVE-2026-27302

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:30:04Z

Weaknesses