Impact
Adobe Campaign Classic (ACC) contains an incorrect authorization flaw that allows attackers to execute arbitrary code within the context of the current user. This vulnerability is a classic case of inadequate access control (CWE‑863) that can lead to full control over the application and potentially the underlying server. The flaw permits execution of any code the current user can run, threatening confidentiality, integrity, and availability of campaign data and system resources.
Affected Systems
The vulnerability affects Adobe Campaign Classic. No specific version information is provided, so all installations of ACC should be considered at risk unless a patch has been applied.
Risk and Exploitability
The CVSS score is 9.1, indicating a high severity. EPSS is not available but the lack of user interaction requirement suggests a high likelihood of exploitation once exposed. The vulnerability is not listed in CISA KEV yet. Based on the description, the likely attack vector is a remote request to the web interface, exploiting improper role checks. The attacker does not need any prior credentials beyond a valid user session, so privileged accounts or even standard users can trigger arbitrary code execution.
OpenCVE Enrichment