Description
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-08-11
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Campaign Classic is vulnerable to an incorrect authorization flaw that allows an attacker to run arbitrary code in the context of the currently logged‑in user. The weakness, classified as CWE‑863, can be exploited without any user interaction, leading to a critical security breach.

Affected Systems

Adobe Campaign Classic (ACC) is the affected product; no specific version information is provided, so any deployment of ACC may be impacted.

Risk and Exploitability

The CVSS score of 10 signals a critical severity, while the EPSS score of less than 1% indicates a very low current exploit probability. This advisory is not listed in CISA KEV. The description states that exploitation does not require user interaction, which implies that an attacker could trigger the flaw remotely, likely through the web interface; this remote abuse potential is inferred from the provided information and is not explicitly stated in the advisory.

Generated by OpenCVE AI on August 12, 2026 at 21:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Campaign Classic security update that fixes the incorrect authorization logic.
  • Limit user accounts to only the permissions required for their roles and restrict administrative access to trusted personnel.
  • Enable comprehensive audit logging and configure alerts for unauthorized privilege modifications or unexpected code execution events so that any exploitation attempts are detected promptly.

Generated by OpenCVE AI on August 12, 2026 at 21:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe campaign
CPEs cpe:2.3:a:adobe:campaign:*:*:*:*:classic:*:*:*
Vendors & Products Adobe campaign

Thu, 13 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe campaign Classic
Vendors & Products Adobe
Adobe campaign Classic

Tue, 11 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Title Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Campaign Campaign Classic
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:33:59.531Z

Reserved: 2026-08-06T11:06:54.736Z

Link: CVE-2026-71398

cve-icon Vulnrichment

Updated: 2026-08-13T14:28:24.343Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T18:18:22.327

Modified: 2026-08-28T00:18:10.477

Link: CVE-2026-71398

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:30:04Z

Weaknesses