CVE-2026-27302
10.0Adobe · Campaign Classic
Adobe Campaign Classic is vulnerable to an incorrect authorization flaw that allows unauthenticated remote attackers to execute arbitrary code without user interaction.
Executive summary
A critical authorization vulnerability in Adobe Campaign Classic allows for unauthenticated remote code execution, posing an extreme risk to infrastructure integrity.
Vulnerability
This vulnerability, categorized as CWE-863, involves an incorrect authorization mechanism that fails to validate user privileges, permitting unauthenticated attackers to execute arbitrary code.
Business impact
The exploitation of this flaw leads to a complete compromise of the affected system, as indicated by the CVSS score of 10.0. Successful attacks result in total loss of confidentiality, integrity, and availability, potentially allowing unauthorized actors to move laterally within the network or exfiltrate sensitive customer data.
Remediation
Immediate Action: Upgrade Adobe Campaign Classic to ACC v7: 7.4.4 build 9400 or later to resolve the authorization failure.
Proactive Monitoring: Inspect server logs for suspicious API calls or unauthorized access requests originating from external IP addresses.
Compensating Controls: Deploy a Web Application Firewall (WAF) to block malicious traffic patterns and restrict access to the Campaign interface to known, trusted management segments.
Exploitation status
Public Exploit Available: No (unknown)
Analyst recommendation
Given the critical nature of this vulnerability and the ease of exploitation, immediate patching is required. Organizations should prioritize updating their Adobe Campaign Classic installations to build 9400 to eliminate the risk of remote code execution.