Description
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-08-03
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Campaign Classic (ACC) suffers from an improper neutralization of directives in code that is evaluated at runtime, allowing an attacker to inject and execute malicious commands. This flaw results in arbitrary code execution with the privileges of the current user, which can be a low‑privileged account. The vulnerability does not require user interaction and the scope is changed, meaning privilege escalation is possible if the compromised account has higher rights. The weakness is identified as CWE‑95.

Affected Systems

Adobe Campaign Classic (ACC) is the affected product. The advisory does not list specific version numbers, so all deployments of ACC are potentially vulnerable until a patch is applied. Because no version information is provided, perform a product inventory check against the Adobe security advisory reference for any applicable releases.

Risk and Exploitability

The CVSS score of 9.6 indicates critical severity. EPSS data is not available, so the exploitation probability is unknown, but the flaw is actively exploitable in the field as the attack does not need user interaction and the scope change allows escalation. The product is not listed in CISA's KEV catalog, however the high CVSS and the lack of a user interaction requirement mean that zero‑day exploitation is likely and could occur at any time. An attacker that can send crafted requests or otherwise inject code into ACC can execute arbitrary commands on the server, compromising confidentiality, integrity, and availability.

Generated by OpenCVE AI on August 4, 2026 at 09:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Adobe security patch or update to the latest ACC release as recommended by the Adobe security advisory at https://helpx.adobe.com/security/products/campaign/apsb26-120.html
  • If an immediate patch is unavailable, restrict access to the components that use evaluative functions and block any dynamic code evaluation from untrusted sources
  • Implement network segmentation and strict access controls to limit the impact of any potential compromise
  • Review and harden the application configuration to disable unused features that may expose eval functionality
  • Monitor the system logs for signs of unusual code execution or privilege escalation activity

Generated by OpenCVE AI on August 4, 2026 at 09:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe campaign Classic
Vendors & Products Adobe
Adobe campaign Classic

Tue, 04 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Description Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Title Adobe Campaign Classic (ACC) | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95)
Weaknesses CWE-95
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Adobe Campaign Campaign Classic
Linux Linux Kernel
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-04T14:12:45.119Z

Reserved: 2026-05-21T15:28:38.137Z

Link: CVE-2026-48317

cve-icon Vulnrichment

Updated: 2026-08-04T14:12:41.347Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-03T23:16:45.930

Modified: 2026-08-06T14:41:17.277

Link: CVE-2026-48317

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T09:45:06Z

Weaknesses
  • CWE-95

    Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')