Description
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain elevated privileges. Exploitation of this issue does not require user interaction.
Published: 2026-08-03
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An incorrect authorization flaw in Adobe Campaign Classic allows an attacker to bypass the intended role‑based access controls and gain elevated privileges. The flaw is identified as CWE‑863 and can enable an adversary to perform functions that should be restricted to higher‑privileged accounts. The potential impact includes full control over campaign data, configuration, and potentially the underlying infrastructure, threatening confidentiality, integrity, and availability of the application.

Affected Systems

Adobe Campaign Classic (ACC) is the affected product. No specific version information is provided in the advisory, so any deployment of ACC should be evaluated for the presence of the incorrect authorization flaw.

Risk and Exploitability

The vulnerability has a CVSS score of 9.8, indicating a critical issue. The EPSS score is not available, and the problem is not listed in the CISA KEV catalog. Exploitation does not require user interaction, implying that an attacker can remotely trigger the privilege escalation through the application’s web interface or API. The combination of high severity, remote attack vector, and lack of user interaction requirements makes it a high‑risk target for attackers.

Generated by OpenCVE AI on August 4, 2026 at 09:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Adobe Campaign Classic to the latest version as detailed in the Adobe security advisory
  • Replace or patch the affected authorization logic to enforce correct role validation
  • Ensure that only trusted accounts have administrative permissions and review role assignments
  • Restrict network access to the Campaign server by using firewall rules or VPN to limit exposure

Generated by OpenCVE AI on August 4, 2026 at 09:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe campaign Classic
Vendors & Products Adobe
Adobe campaign Classic

Tue, 04 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Description Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain elevated privileges. Exploitation of this issue does not require user interaction.
Title Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Campaign Campaign Classic
Linux Linux Kernel
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-04T14:14:45.431Z

Reserved: 2026-05-21T15:28:38.139Z

Link: CVE-2026-48333

cve-icon Vulnrichment

Updated: 2026-08-04T14:14:41.208Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-03T23:16:46.567

Modified: 2026-08-06T14:41:40.413

Link: CVE-2026-48333

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T09:45:06Z

Weaknesses