Description
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-09-22
Score: 9.6 Critical
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

Adobe Campaign Classic is vulnerable to a Server‑Side Request Forgery that can be triggered by a low‑privileged user without any user interaction. The flaw allows the attacker to direct the application to query arbitrary internal resources, effectively granting the attacker elevated access and the ability to read or modify sensitive data. The weakness is classified as CWE‑918, which indicates improper validation of user‑supplied URLs.

Affected Systems

Adobe Campaign Classic (ACC) from Adobe is the affected product. Specific affected versions are not listed in the advisory; organizations should verify whether their installed version is within the scope of the issue.

Risk and Exploitability

The CVSS score of 9.6 reflects a high severity and the scope change confirms that privileges can be escalated once the SSRF is exploited. EPSS data is not available, but the lack of a known KEV listing does not reduce the risk; the flaw remains exploitable in the wild if the application is accessed by a low‑privileged user. The likely attack vector is an SSRF request originating from the ACC server to internal services, which does not require user interaction and therefore can be automated.

Generated by OpenCVE AI on September 22, 2026 at 18:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Campaign Classic patch released by Adobe as per the security advisory.
  • If a patch is not yet available, block outbound connections from the ACC server to internal IP ranges to prevent accidental SSRF abuse.
  • Enable comprehensive logging of all outbound HTTP requests from ACC and monitor for unexpected destinations to detect potential exploitation attempts.

Generated by OpenCVE AI on September 22, 2026 at 18:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe campaign Classic
Vendors & Products Adobe
Adobe campaign Classic

Tue, 22 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed.
Title Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Adobe Campaign Classic
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-22T18:36:56.584Z

Reserved: 2026-08-29T11:08:24.946Z

Link: CVE-2026-82443

cve-icon Vulnrichment

Updated: 2026-09-22T18:36:53.110Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T18:17:21.790

Modified: 2026-09-22T19:16:53.647

Link: CVE-2026-82443

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T19:00:12Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)