Description
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-09-22
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: Privilege Escalation via SSRF
Action: Immediate Patch
AI Analysis

Impact

Adobe Campaign Classic is vulnerable to a server‑side request forgery that can lead to privilege escalation. The flaw allows an attacker to instruct the application to make arbitrary HTTP requests, potentially to internal resources, and the affected scope is changed, meaning the attacker could gain higher privileges than the application’s normal permissions.

Affected Systems

Adobe Campaign Classic is the only product listed as affected; no specific version ranges are supplied in the available data, so all installations of Adobe Campaign Classic should be considered at risk until a vendor fix is released.

Risk and Exploitability

The CVSS score of 9.9 indicates critical severity. The EPSS score is not available, so current exploitation probability is unknown. The vulnerability is not listed in CISA's KEV catalog. Based on the description, it is inferred that the attack vector is remote network-based and no user interaction is required, implying that an attacker could exploit the flaw from outside the organization if they can reach the application. The scope change indicates that exploitation could affect broader system components or other users.

Generated by OpenCVE AI on September 22, 2026 at 18:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor-provided patch or upgrade to a fixed version of Adobe Campaign Classic as soon as it becomes available.
  • Configure the application’s network settings to restrict outbound traffic to a whitelist of approved hosts and ports, thereby limiting the impact of any SSRF attempts.
  • Implement input validation to ensure that URLs supplied to the application are sanitized and only allow safe protocols (e.g., https) and trusted domains.

Generated by OpenCVE AI on September 22, 2026 at 18:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe campaign Classic
Vendors & Products Adobe
Adobe campaign Classic

Tue, 22 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.
Title Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L'}


Subscriptions

Adobe Campaign Classic
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-22T17:40:02.308Z

Reserved: 2026-08-31T22:35:14.086Z

Link: CVE-2026-83660

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T18:17:22.673

Modified: 2026-09-22T19:05:50.323

Link: CVE-2026-83660

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T19:00:13Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)