Description
Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-09-22
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

Adobe Campaign Classic is vulnerable to an improper control of code generation flaw that permits attackers to inject and execute arbitrary code under the permissions of the current user. The vulnerability stems from insecure handling of user-supplied input in dynamic code contexts, leading to a code injection weakness. An attacker exploiting this flaw can run arbitrary programs on the affected instance, potentially compromising confidentiality, integrity, and availability of data and services within the scope of the compromised application.

Affected Systems

The affected product is Adobe Campaign Classic as distributed by Adobe. No specific version list is provided in the CNA data, so all currently deployed installations of Adobe Campaign Classic are at risk until a vendor update is applied.

Risk and Exploitability

The flaw carries a CVSS score of 10, indicating the highest level of severity. No EPSS score is available, but the lack of user interaction and scope changes suggest the vulnerability can be leveraged remotely by an unauthenticated or authenticated adversary depending on their privileges. Because it is not listed in CISA’s KEV catalog, no actively deployed exploit is confirmed; however, the combination of a high impact rating and the potential for remote exploitation makes it a high-priority target for attackers.

Generated by OpenCVE AI on September 22, 2026 at 18:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Campaign Classic patch or update to the vendor‑released secure version immediately.
  • Limit or disable functionality that permits dynamic code generation or execution by untrusted input, such as customizable script blocks or template compilations, whenever possible.
  • Enforce strict role‑based access controls so that only trusted administrators can modify code‑containing components or create new scripts.
  • Monitor application logs for anomalous execution patterns and set up alerts for unexpected outbound connections that may indicate exploitation.
  • If a patch is unavailable in the short term, isolate the affected system from network access that is not strictly necessary.

Generated by OpenCVE AI on September 22, 2026 at 18:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe campaign Classic
Vendors & Products Adobe
Adobe campaign Classic

Tue, 22 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Title Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94)
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Campaign Classic
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-22T17:39:54.722Z

Reserved: 2026-08-12T11:06:21.480Z

Link: CVE-2026-73369

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T18:17:15.300

Modified: 2026-09-22T19:05:50.323

Link: CVE-2026-73369

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T19:00:12Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')