Description
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-09-22
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Apply Fix ASAP
AI Analysis

Impact

Adobe Campaign Classic is vulnerable to an incorrect authorization flaw that can lead to arbitrary code execution in the context of the affected user. The flaw allows an attacker to execute code without relying on user interaction, potentially granting full system compromise. The weakness is classified as CWE‑863, indicating that insufficient authorization checks are present within the application.

Affected Systems

Adobe Campaign Classic installations are affected. No specific version range is provided, so all deployments should assume the vulnerability is present until a vendor update is applied.

Risk and Exploitability

The CVSS score of 10 indicates a critical risk, and exploitation does not require user interaction, implying that a remote attacker can trigger the vulnerability directly. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. The scope change indicates that the flaw can affect all users of the system, potentially escalating from a single compromised account to full administrative control. The attack vector is inferred to be remote, via the web interface, given that no user interaction is required.

Generated by OpenCVE AI on September 22, 2026 at 18:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch for Adobe Campaign Classic as soon as it is released
  • Restrict administrative access to the ACC web interface to trusted users only
  • Enable detailed logging of privileged actions and monitor for suspicious activity

Generated by OpenCVE AI on September 22, 2026 at 18:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe campaign Classic
Vendors & Products Adobe
Adobe campaign Classic

Tue, 22 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Title Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Campaign Classic
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-22T18:33:50.834Z

Reserved: 2026-08-18T01:29:54.621Z

Link: CVE-2026-75723

cve-icon Vulnrichment

Updated: 2026-09-22T18:33:34.960Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T18:17:16.163

Modified: 2026-09-22T19:16:47.140

Link: CVE-2026-75723

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T19:00:12Z

Weaknesses