Impact
An incorrect authorization flaw in Adobe Campaign Classic allows an attacker to bypass the intended role‑based access controls and gain elevated privileges. The flaw is identified as CWE‑863 and can enable an adversary to perform functions that should be restricted to higher‑privileged accounts. The potential impact includes full control over campaign data, configuration, and potentially the underlying infrastructure, threatening confidentiality, integrity, and availability of the application.
Affected Systems
Adobe Campaign Classic (ACC) is the affected product. No specific version information is provided in the advisory, so any deployment of ACC should be evaluated for the presence of the incorrect authorization flaw.
Risk and Exploitability
The vulnerability has a CVSS score of 9.8, indicating a critical issue. The EPSS score is not available, and the problem is not listed in the CISA KEV catalog. Exploitation does not require user interaction, implying that an attacker can remotely trigger the privilege escalation through the application’s web interface or API. The combination of high severity, remote attack vector, and lack of user interaction requirements makes it a high‑risk target for attackers.
OpenCVE Enrichment