Description
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-08-25
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Campaign Classic is vulnerable to an OS command injection flaw that allows an attacker to execute arbitrary code in the context of the current user. The vulnerability arises from improper neutralization of special elements used in an OS command and can be exploited without any user interaction. Consequently, successful exploitation results in the compromise of the application’s process and, if unmitigated, could extend to the underlying operating system depending on user privileges. The vendor has classified the impact scope as changed, indicating that the flaw can affect components beyond the initially intended boundaries.

Affected Systems

All installations of Adobe Campaign Classic are impacted; the advisory does not specify version ranges, so any deployed version without a pending patch should be considered vulnerable.

Risk and Exploitability

The CVSS score of 10 marks this flaw as critical, and while an EPSS score is not provided, the lack of a KEV listing does not diminish the inherent risk. Based on the description, the likely attack vector is a remote web‑based exploit targeting the Campaign Classic application’s CLI interface, permitting an attacker to send a crafted command without needing interaction. The scope change plus the high severity indicate that once exploited, an attacker could gain significant control over the affected system.

Generated by OpenCVE AI on August 25, 2026 at 19:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Campaign Classic patch or upgrade to a version that fixes the OS command injection flaw.
  • If a patch is not yet available, restrict external access to the Campaign Classic servers using firewall rules or network segmentation to reduce exposure to potential attackers.
  • Monitor system and application logs for abnormal command execution attempts and enforce strict input validation on any custom code that interacts with the command line interface.

Generated by OpenCVE AI on August 25, 2026 at 19:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Title Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-25T17:27:10.836Z

Reserved: 2026-08-19T11:08:51.381Z

Link: CVE-2026-76197

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T18:18:05.110

Modified: 2026-08-25T18:18:05.110

Link: CVE-2026-76197

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T19:15:05Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')