Impact
Adobe Campaign Classic is vulnerable to an incorrect authorization flaw that allows an attacker to run arbitrary code in the context of the currently logged‑in user. The weakness, classified as CWE‑863, can be exploited without any user interaction, leading to a critical security breach.
Affected Systems
Adobe Campaign Classic (ACC) is the affected product; no specific version information is provided, so any deployment of ACC may be impacted.
Risk and Exploitability
The CVSS score of 10 signals a critical severity, while the EPSS score of less than 1% indicates a very low current exploit probability. This advisory is not listed in CISA KEV. The description states that exploitation does not require user interaction, which implies that an attacker could trigger the flaw remotely, likely through the web interface; this remote abuse potential is inferred from the provided information and is not explicitly stated in the advisory.
OpenCVE Enrichment