Adobe Campaign Classic is vulnerable to an OS Command Injection, allowing unauthenticated attackers to execute arbitrary code on the host system.
Description
Adobe Campaign Classic is vulnerable to an OS Command Injection, allowing unauthenticated attackers to execute arbitrary code on the host system.
AI Analyst Comment
Remediation
Update Adobe Adobe Campaign Classic to the latest version. Check the vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
Description Summary:
Adobe Campaign Classic is vulnerable to an OS Command Injection, allowing unauthenticated attackers to execute arbitrary code on the host system.
Executive Summary:
Adobe Campaign Classic is vulnerable to a critical OS Command Injection flaw, enabling unauthenticated attackers to execute arbitrary code and gain full control of the host system.
Vulnerability Details
CVE-ID: CVE-2026-76197
Affected Software: Adobe Campaign Classic
Affected Versions: 0 through ACC v7: 7.4.4 build 9400
Vulnerability: This is an OS Command Injection (CWE-78) vulnerability. It is exploitable by unauthenticated remote attackers and does not require user interaction.
Business Impact
The CVSS score of 10.0 indicates a maximum severity, highlighting the critical threat to business operations. Successful exploitation allows for complete system compromise, which can result in severe financial, reputational, and operational damage.
Remediation Plan
Immediate Action: Update the affected Adobe Campaign Classic software to build 9401 or later.
Proactive Monitoring: Review system process logs for unauthorized or unexpected command execution patterns associated with the application environment.
Compensating Controls: Implement strict input validation at the WAF level to identify and filter out payloads that attempt to inject OS commands.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of August 25, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The nature of the flaw makes it a primary target for automated exploitation tools if a PoC is developed.
Analyst Recommendation
Given the critical CVSS rating, immediate remediation is essential. Administrators must verify that all Adobe Campaign Classic deployments are patched to build 9401 to mitigate the risk of remote code execution.