Impact
Adobe Campaign Classic is vulnerable to a Server‑Side Request Forgery that can lead to privilege escalation. An attacker who can send a specially crafted request to the ACC service could force the server to make requests to internal resources, effectively enabling the attacker to access and potentially modify resources that were otherwise protected. Because the vulnerability is a privilege escalation path, exploitation changes the scope of the affected account from low to higher privileges.
Affected Systems
Adobe Campaign Classic is affected. No specific version information is provided in the CVE entry; the vulnerability applies to installations of Adobe Campaign Classic that have not applied the recent update. Administrators should verify which version of Campaign Classic they are running and compare against the Adobe security advisory at the provided link.
Risk and Exploitability
The CVSS score of 9.9 indicates a critical severity. The EPSS score is not available, so the current estimate of exploitation probability is unknown. The vulnerability does not require user interaction and the attack surface is limited to the service itself, but because it can be used for privilege escalation, a successful exploitation could grant an attacker elevated access to internal resources. The problem is not listed in CISA’s KEV catalog, so there is currently no evidence of widespread active exploitation, but the critical CVSS score warrants immediate attention.
OpenCVE Enrichment