Description
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-08-25
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of special elements used in an OS command, allowing an attacker to inject arbitrary commands. This can lead to execution of code in the context of the current user, even without any user interaction. The change of scope indicates that the impact may extend beyond the original context.

Affected Systems

Adobe Campaign Classic is the affected product. No specific versions are listed in the CNA data, so the vulnerability could potentially affect any deployed instance of Adobe Campaign Classic until patched.

Risk and Exploitability

The CVSS score of 10 indicates critical severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, but the lack of exploitation data does not diminish the risk. The attack likely exploits a command injection point exposed by Adobe Campaign Classic through web or API interfaces; based on the description, it is inferred that an attacker could trigger the flaw remotely without needing to log in. Once injected, code runs in the context of the current user, allowing arbitrary action and potentially full control of the host.

Generated by OpenCVE AI on August 25, 2026 at 21:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Adobe patch or upgrade to a version that contains the fix for CVE-2026-76195 on all Campaign Classic installations.
  • If a patch is not immediately available, restrict access to the endpoints that invoke OS commands, and enforce network segmentation to limit exposure of the vulnerable service.
  • Enable verbose logging for command execution and monitor logs for anomalous activity, and revoke or limit administrative privileges for the affected service to reduce potential impact.

Generated by OpenCVE AI on August 25, 2026 at 21:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Title Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-25T17:50:20.470Z

Reserved: 2026-08-19T11:07:57.285Z

Link: CVE-2026-76195

cve-icon Vulnrichment

Updated: 2026-08-25T17:50:15.733Z

cve-icon NVD

Status : Received

Published: 2026-08-25T18:18:04.967

Modified: 2026-08-25T18:18:04.967

Link: CVE-2026-76195

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T19:15:05Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')