Description
Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-09-22
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: Remote code execution
Action: Immediate Patch
AI Analysis

Impact

Adobe Campaign Classic is affected by an Improper Control of Generation of Code vulnerability that permits the execution of arbitrary code within the context of the current user. The flaw is a classic code injection issue, identified as CWE‑94, and is exploitable without any user interaction.

Affected Systems

Adobe Campaign Classic (ACC) is the affected product. No specific version information was disclosed in the data provided.

Risk and Exploitability

The CVSS score of 10 reflects a maximum severity rating, and the scope is noted as changed, indicating that compromise of a single user could affect higher‑level privileges. The EPSS score is not available, but the absence of a KEV listing does not diminish the criticality of the flaw. An attacker can leverage this injection without needing the victim’s input, making the vulnerability highly attractive for exploitation.

Generated by OpenCVE AI on September 22, 2026 at 18:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Campaign Classic security update released in Adobe Product Security Bulletin APSB26‑142.
  • If patching is delayed, limit the permissions of the Campaign user account to the least privileges required and disable any runtime code generation features through configuration settings.
  • Configure logging and monitoring for unusual execution or configuration changes, and review logs for signs of exploitation.

Generated by OpenCVE AI on September 22, 2026 at 18:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe campaign Classic
Vendors & Products Adobe
Adobe campaign Classic

Tue, 22 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Title Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94)
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Campaign Classic
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-22T17:39:51.857Z

Reserved: 2026-09-11T11:15:11.448Z

Link: CVE-2026-89275

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T18:17:29.407

Modified: 2026-09-22T19:05:50.323

Link: CVE-2026-89275

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T19:00:12Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')