Description
Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-09-22
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: Arbitrary code execution
Action: Apply patch
AI Analysis

Impact

Adobe Campaign Classic contains an Improper Control of Generation of Code flaw (CWE‑94). An attacker can cause the application to evaluate attacker‑supplied input as executable code, allowing arbitrary code execution in the context of the user who is logged in. Because the vulnerability does not require any user interaction, a low‑privileged attacker who can reach the application can run commands and potentially further exploit the system.

Affected Systems

Adobe Campaign Classic is affected. Specific product versions are not listed in the advisory, so all current installations of the platform should be treated as vulnerable until a vendor fix is applied.

Risk and Exploitability

The flaw carries a CVSS score of 9.9, indicating critical severity. EPSS data is unavailable, and the issue is not yet listed in the CISA KEV catalog. Successful exploitation would provide an attacker with the privileges of the affected user; the change in scope suggests the possibility of privilege escalation beyond the initial user context. Because no user interaction is required, the risk of exploitation is high even for simply monitoring traffic or reviewing logs.

Generated by OpenCVE AI on September 22, 2026 at 18:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Adobe Campaign Classic security update released in accordance with Adobe's security advisory for CVE‑2026‑89276.
  • If a patch is not yet available, restrict or disable any features that allow dynamic code evaluation, such as template scripting, and block the administration interface from untrusted networks.
  • Implement least‑privilege policies for user accounts and monitor for unexpected script execution activity to detect potential exploitation.

Generated by OpenCVE AI on September 22, 2026 at 18:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe campaign Classic
Vendors & Products Adobe
Adobe campaign Classic

Tue, 22 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Title Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94)
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L'}


Subscriptions

Adobe Campaign Classic
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-22T17:40:02.979Z

Reserved: 2026-09-11T11:15:11.448Z

Link: CVE-2026-89276

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T18:17:29.550

Modified: 2026-09-22T19:05:50.323

Link: CVE-2026-89276

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T19:00:13Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')