Description
Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction.
Published: 2026-08-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Campaign Classic has a violation of secure design principles that permits a security feature bypass; an attacker can use this flaw to gain unauthorized read access to data. The weakness is a failure to enforce proper security constraints, allowing privileged operations to be performed without appropriate checks. The impact includes potential exposure of confidential information and could compromise the integrity of the system's data safeguarding.

Affected Systems

Adobe:Adobe Campaign Classic is impacted. No specific version information is listed, so all deployed instances are presumed vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity level. Exploitation does not require user interaction, implying that an attacker can trigger the vulnerability remotely, potentially from any network-connected location that can reach the application. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits yet, but the high score and lack of user interaction mean the risk is significant. The attack path is likely to involve sending crafted requests to the application that bypass normal security controls, thus giving unauthorized read capability.

Generated by OpenCVE AI on August 4, 2026 at 09:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Campaign Classic security patch or upgrade to a supported version that addresses the secure design principle violation.
  • Restrict network access to the Campaign Classic installation by placing it behind a firewall or VPN and limiting inbound connections to trusted administrative hosts.
  • Enforce strict role‑based access controls and audit permissions to ensure that only authorized users can read sensitive data.

Generated by OpenCVE AI on August 4, 2026 at 09:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe campaign Classic
Vendors & Products Adobe
Adobe campaign Classic

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Description Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction.
Title Adobe Campaign Classic (ACC) | Violation of Secure Design Principles (CWE-657)
Weaknesses CWE-657
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Adobe Campaign Campaign Classic
Linux Linux Kernel
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-04T15:43:54.855Z

Reserved: 2026-05-21T15:28:38.143Z

Link: CVE-2026-48399

cve-icon Vulnrichment

Updated: 2026-08-04T15:43:45.572Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-03T23:16:46.693

Modified: 2026-08-06T14:41:44.503

Link: CVE-2026-48399

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T09:45:06Z

Weaknesses
  • CWE-657

    Violation of Secure Design Principles