Description
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-08-25
Score: 10 Critical
EPSS: 1.6% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Adobe Campaign Classic contains an OS command injection vulnerability caused by improper neutralization of special elements. Attackers can inject crafted commands that are executed with the privileges of the current user, potentially enabling arbitrary code execution. The flaw is exploitable without any user interaction and a scope change indicates that impact may extend beyond the originally affected components.

Affected Systems

All installations of Adobe Campaign Classic are susceptible unless patched. No specific version ranges are identified; any deployed instance lacking a fix should be considered vulnerable.

Risk and Exploitability

The CVSS score of 10 marks it as critical, and the EPSS score of 1% indicates a very low yet non‑zero likelihood of exploitation; the absence of a KEV listing does not reduce the risk. The likely attack vector is remote, via crafted input to the application’s command interface or API, enabling a threat actor to execute arbitrary OS commands. Because exploitation does not require interaction, exposure to external traffic makes the vulnerability highly actionable.

Generated by OpenCVE AI on August 26, 2026 at 14:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Campaign Classic patch or upgrade to a version that fixes the OS command injection flaw.
  • If a patch is not yet available, restrict external access to the Campaign Classic servers using firewall rules or network segmentation to reduce exposure to potential attackers.
  • Monitor system and application logs for abnormal command execution attempts and enforce strict input validation on any custom code that interacts with the command line interface.

Generated by OpenCVE AI on August 26, 2026 at 14:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe campaign
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:campaign:*:*:*:*:classic:*:*:*
cpe:2.3:a:adobe:campaign:7.4.1:9383:*:*:classic:*:*:*
cpe:2.3:a:adobe:campaign:7.4.2:9390:*:*:classic:*:*:*
cpe:2.3:a:adobe:campaign:7.4.2:9391:*:*:classic:*:*:*
cpe:2.3:a:adobe:campaign:7.4.3:9394:*:*:classic:*:*:*
cpe:2.3:a:adobe:campaign:7.4.3:9396:*:*:classic:*:*:*
cpe:2.3:a:adobe:campaign:7.4.3:9397:*:*:classic:*:*:*
cpe:2.3:a:adobe:campaign:7.4.3:9398:*:*:classic:*:*:*
cpe:2.3:a:adobe:campaign:7.4.3:9399:*:*:classic:*:*:*
cpe:2.3:a:adobe:campaign:7.4.4:9400:*:*:classic:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe campaign
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Sun, 30 Aug 2026 00:30:00 +0000


Sun, 30 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
References

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Title Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Campaign
Linux Linux Kernel
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-29T23:54:29.865Z

Reserved: 2026-08-19T11:08:51.381Z

Link: CVE-2026-76197

cve-icon Vulnrichment

Updated: 2026-08-27T16:15:34.319Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T18:18:05.110

Modified: 2026-09-01T19:05:02.847

Link: CVE-2026-76197

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T14:45:04Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')