Adobe Campaign Classic contains an incorrect authorization vulnerability that permits unauthenticated remote attackers to achieve arbitrary code execu...
Description
Adobe Campaign Classic contains an incorrect authorization vulnerability that permits unauthenticated remote attackers to achieve arbitrary code execution.
AI Analyst Comment
Remediation
Update Adobe Adobe Campaign Classic to the latest version. Check the vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Adobe
PRODUCT: Campaign Classic
AFFECTED_VERSIONS: 0 through ACC v7: 7.4.3 build 9399
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
Adobe Campaign Classic contains an incorrect authorization vulnerability that permits unauthenticated remote attackers to achieve arbitrary code execution.
Executive Summary:
A critical authorization vulnerability in Adobe Campaign Classic enables unauthenticated remote code execution, threatening the entire application environment.
Vulnerability Details
CVE-ID: CVE-2026-71398
Affected Software: Adobe Campaign Classic
Affected Versions: 0 through ACC v7: 7.4.3 build 9399
Vulnerability: The software suffers from an incorrect authorization flaw (CWE-863) that allows an unauthenticated, remote attacker to bypass security controls and execute arbitrary code.
Business Impact
With a CVSS score of 10.0, this vulnerability represents a maximum-severity risk. Successful exploitation grants an attacker full control over the application, leading to potential data breaches, unauthorized system modifications, and significant operational disruption.
Remediation Plan
Immediate Action: Update Adobe Campaign Classic to ACC v7: 7.4.4 build 9400 immediately to apply the necessary authorization fixes.
Proactive Monitoring: Review system access logs for anomalous activity and monitor for unexpected service execution processes that may indicate exploitation attempts.
Compensating Controls: Implement strict network-level access controls to ensure the Campaign Classic interface is not exposed to the public internet.
Exploitation Status
Public Exploit Available: No (unknown)
Analyst Notes: As of Aug 11, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently dangerous due to its lack of authentication requirements.
Analyst Recommendation
The severity of this vulnerability necessitates immediate remediation. Security teams must ensure all instances of Adobe Campaign Classic are updated to the specified patch level to mitigate the risk of unauthorized remote code execution.