Impact
The vulnerability is an instance of code injection, identified as CWE‑94. The flaw allows an attacker to supply input that is interpreted as executable code by Adobe Campaign Classic. Because the code runs with the privileges of the current user, successful exploitation results in arbitrary code execution in that context. The description states that no user interaction is required and that the scope is changed, indicating the potential for privilege escalation beyond the initial context.
Affected Systems
All deployments of Adobe Campaign Classic are affected, with no specific version restrictions reported in the CNA data. Administrators should consult Adobe’s security advisory (APSb26142) for details on vulnerabilities that affect their installed version. In the absence of version information, any instance that has not applied the available patch or update should be considered vulnerable until confirmed otherwise.
Risk and Exploitability
The CVSS base score is 10, the highest possible, and no EPSS value is supplied; therefore the exploitation likelihood cannot be quantified but is presumed significant given the severity. The vulnerability is not currently listed in CISA’s KEV catalog, but the lack of listing does not diminish the risk. Based on the description, it is inferred that the attacker can trigger the code injection remotely via exposed APIs or UI, which allows arbitrary code execution in the context of the current user. The scope is changed, meaning the risk could affect the broader system environment.
OpenCVE Enrichment