Impact
Adobe Campaign Classic is vulnerable to an incorrect authorization flaw that allows an attacker to execute code in the context of the currently logged‑in user. The vulnerability can be triggered without any user interaction and has been marked as a scope changing issue, meaning that privileges could be escalated to system‑wide level. The flaw is categorized as CWE‑863, which indicates that authorisation controls are improperly implemented.
Affected Systems
Adobe Campaign Classic is the only affected product listed. No specific version numbers are provided in the available data, so all installations of Adobe Campaign Classic are potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 10.0 places this vulnerability in the critical range. While the EPSS score is reported as less than 1%, indicating a low overall exploitation probability at this time, the flaw could still be leveraged by advanced threat actors. The likely attack vector involves the web or API interfaces of the application, though the exact details are not explicitly documented. The vulnerability is not currently listed in the CISA KEV catalog, but the high severity and scope‑changing nature warrant rapid detection and remediation.
OpenCVE Enrichment