Description
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-08-25
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Campaign Classic is affected by a Server‑Side Request Forgery vulnerability that allows an attacker to send arbitrary HTTP requests to internal or external services from the server. The flaw can be leveraged to execute arbitrary code in the context of the user running the application, leading to a full compromise of the application and potentially the underlying host. The weakness corresponds to CWE‑918, which can grant attackers the ability to instruct the server to reach addresses outside the intended scope, bypassing network isolation and enabling code execution.

Affected Systems

The vulnerability affects Adobe Campaign Classic from Adobe. No specific version range is listed in the advisory, so all deployed instances of this product should be checked for applicability.

Risk and Exploitability

The CVSS score of 10 indicates a critical severity. With no EPSS score available, the exploitation probability is uncertain, but the lack of user interaction requirement and scope change mean that a compromised site can be fully taken over. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an unauthenticated or low‑privilege attacker triggering the SSRF endpoint, which then forces the server to contact a malicious host that delivers payloads leading to code execution.

Generated by OpenCVE AI on August 25, 2026 at 19:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Confirm whether Adobe Campaign Classic is installed and determine its current version
  • Apply any vendor patch or update that addresses the SSRF flaw as soon as it is released
  • If a patch is not yet available, restrict outbound network traffic from the application or isolate the server in a sub‑network to block unwanted requests
  • Monitor application logs for unusual outbound HTTP requests and review inventory for exposed endpoints

Generated by OpenCVE AI on August 25, 2026 at 19:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Title Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-25T17:27:10.140Z

Reserved: 2026-08-19T11:07:21.444Z

Link: CVE-2026-76193

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T18:18:04.813

Modified: 2026-08-25T18:18:04.813

Link: CVE-2026-76193

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T19:15:05Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)