Description
Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-06-09
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Campaign Classic versions 7.4.3 build 9394 and earlier contain an incorrect authorization flaw (CWE‑863) that allows an attacker to execute arbitrary code in the context of the user who accesses the system. The vulnerability does not require any user interaction, and the flaw changes the security scope, giving the attacker full control over the affected instance. An attacker who can reach the affected functions could run malicious code and compromise the confidentiality, integrity, and availability of the application and its underlying data.

Affected Systems

The affected products are Adobe Campaign Classic (ACC) from Adobe. Users running ACC version 7.4.3 build 9394 or earlier are at risk. No other versions are listed as affected.

Risk and Exploitability

The CVSS score of 10 indicates maximum severity, and the lack of an EPSS score does not diminish the high likelihood that an attacker with sufficient resources could target an exposed instance. The vulnerability does not require user interaction, so a remote attacker could exploit the flaw through exposed web interfaces or APIs. Because the flaw changes scope, a single mis‑authorized action can lead to full compromise. The vulnerability is not listed in CISA's KEV catalog, but its criticality warrants immediate attention. The likely attack vector is inferred to be via a public‑facing service such as a web application or API, based on the description stating no user interaction is needed and that scope is changed.

Generated by OpenCVE AI on June 9, 2026 at 22:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Campaign Classic patch or upgrade past version 7.4.3 build 9394.
  • Enforce the principle of least privilege by reducing the permissions of all application users and disabling unused accounts.
  • Institute continuous monitoring of web and API traffic for abnormal behavior, and configure a web application firewall to block unauthorized requests.

Generated by OpenCVE AI on June 9, 2026 at 22:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 09 Jun 2026 21:15:00 +0000

Type Values Removed Values Added
Description Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Title Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-06-09T20:59:03.860Z

Reserved: 2026-05-21T15:28:38.136Z

Link: CVE-2026-48303

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-09T21:17:25.510

Modified: 2026-06-09T21:17:25.510

Link: CVE-2026-48303

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-09T22:45:05Z

Weaknesses