Description
Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-09-22
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: Arbitrary Code Execution
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is an instance of code injection, identified as CWE‑94. The flaw allows an attacker to supply input that is interpreted as executable code by Adobe Campaign Classic. Because the code runs with the privileges of the current user, successful exploitation results in arbitrary code execution in that context. The description states that no user interaction is required and that the scope is changed, indicating the potential for privilege escalation beyond the initial context.

Affected Systems

All deployments of Adobe Campaign Classic are affected, with no specific version restrictions reported in the CNA data. Administrators should consult Adobe’s security advisory (APSb26142) for details on vulnerabilities that affect their installed version. In the absence of version information, any instance that has not applied the available patch or update should be considered vulnerable until confirmed otherwise.

Risk and Exploitability

The CVSS base score is 10, the highest possible, and no EPSS value is supplied; therefore the exploitation likelihood cannot be quantified but is presumed significant given the severity. The vulnerability is not currently listed in CISA’s KEV catalog, but the lack of listing does not diminish the risk. Based on the description, it is inferred that the attacker can trigger the code injection remotely via exposed APIs or UI, which allows arbitrary code execution in the context of the current user. The scope is changed, meaning the risk could affect the broader system environment.

Generated by OpenCVE AI on September 22, 2026 at 18:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch released by Adobe to address the code injection flaw, as detailed in the APSb26-142 advisory.
  • If the patch is not yet available, restrict the use of any functionality that evaluates user‑supplied code, such as disabling custom scripting or template features until a fix is applied.
  • Upgrade Adobe Campaign Classic to the latest version that incorporates the security fix, ensuring that all components are current.
  • Isolate the Adobe Campaign Classic installation from the rest of the network, restricting access to trusted administrators and minimizing exposure to external clients.
  • Monitor application logs for unexpected code execution or abnormal behavior and investigate any incidents promptly.

Generated by OpenCVE AI on September 22, 2026 at 18:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Title Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94)
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-22T18:37:57.814Z

Reserved: 2026-08-18T01:29:54.619Z

Link: CVE-2026-75703

cve-icon Vulnrichment

Updated: 2026-09-22T18:37:17.623Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T18:17:15.900

Modified: 2026-09-22T19:16:47.037

Link: CVE-2026-75703

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T19:00:13Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')