Description
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-09-22
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: Privilege Escalation via SSRF
Action: Patch Now
AI Analysis

Impact

Adobe Campaign Classic is vulnerable to a Server‑Side Request Forgery that can lead to privilege escalation. An attacker who can send a specially crafted request to the ACC service could force the server to make requests to internal resources, effectively enabling the attacker to access and potentially modify resources that were otherwise protected. Because the vulnerability is a privilege escalation path, exploitation changes the scope of the affected account from low to higher privileges.

Affected Systems

Adobe Campaign Classic is affected. No specific version information is provided in the CVE entry; the vulnerability applies to installations of Adobe Campaign Classic that have not applied the recent update. Administrators should verify which version of Campaign Classic they are running and compare against the Adobe security advisory at the provided link.

Risk and Exploitability

The CVSS score of 9.9 indicates a critical severity. The EPSS score is not available, so the current estimate of exploitation probability is unknown. The vulnerability does not require user interaction and the attack surface is limited to the service itself, but because it can be used for privilege escalation, a successful exploitation could grant an attacker elevated access to internal resources. The problem is not listed in CISA’s KEV catalog, so there is currently no evidence of widespread active exploitation, but the critical CVSS score warrants immediate attention.

Generated by OpenCVE AI on September 22, 2026 at 18:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patch released by Adobe for Adobe Campaign Classic that addresses the SSRF flaw.
  • Configure the application to reject outbound requests to internal networks by blocking RFC1918 IP ranges or using outbound firewall rules.
  • Implement strict input validation or whitelisting of URLs that the application is allowed to request to mitigate SSRF risks.

Generated by OpenCVE AI on September 22, 2026 at 18:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe campaign Classic
Vendors & Products Adobe
Adobe campaign Classic

Tue, 22 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed.
Title Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Campaign Classic
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-22T17:40:01.616Z

Reserved: 2026-08-27T21:20:45.369Z

Link: CVE-2026-82013

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T18:17:21.657

Modified: 2026-09-22T19:05:50.323

Link: CVE-2026-82013

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T19:00:12Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)