Description
Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-09-22
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Adobe Campaign Classic contains an Improper Input Validation flaw that allows a low‑privileged attacker to execute arbitrary code in the context of the authenticated user. The flaw does not require user interaction and the scope is changed, meaning that once exploited the attacker can gain broader system access. Because the vulnerability permits arbitrary code execution, the potential loss includes full compromise of the campaign service, disclosure or loss of customer data, and irrecoverable availability impact.

Affected Systems

Adobe Campaign Classic installations are vulnerable. No specific version ranges are listed in the advisory, so all deployed instances should be assessed. The advisory references Adobe’s security bulletin, but does not provide version qualifiers.

Risk and Exploitability

The CVSS score of 9.9 indicates critical severity. While no EPSS score is available, the lack of a KEV listing does not negate the risk. Attackers can exploit the flaw by injecting malformed input into the application without needing any user interaction. Because the vulnerability changes scope, an attacker with minimal privileges can elevate privileges and affect the entire system. The exploit is straightforward, suggesting a high likelihood of real‑world exploitation if not immediately remediated.

Generated by OpenCVE AI on September 22, 2026 at 18:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and apply the Adobe Campaign Classic security patch described in the Adobe Security Bulletin (https://helpx.adobe.com/security/products/campaign/apsb26-142.html).
  • Ensure that all custom input handling in the application is validated using strict data type and length checks, following the CWE‑20 guidelines to prevent arbitrary code execution.
  • Restrict access to the application by enforcing least‑privilege user roles, and disable or remove unused low‑privileged accounts that could otherwise exploit the vulnerability.

Generated by OpenCVE AI on September 22, 2026 at 18:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe campaign Classic
Vendors & Products Adobe
Adobe campaign Classic

Tue, 22 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Title Adobe Campaign Classic (ACC) | Improper Input Validation (CWE-20)
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Campaign Classic
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-22T18:35:20.695Z

Reserved: 2026-08-27T21:20:45.368Z

Link: CVE-2026-82008

cve-icon Vulnrichment

Updated: 2026-09-22T18:35:16.029Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T18:17:21.077

Modified: 2026-09-22T19:16:53.427

Link: CVE-2026-82008

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T19:00:12Z

Weaknesses
  • CWE-20

    Improper Input Validation