CVE-2026-27302

10.0

Adobe · Campaign Classic

Adobe Campaign Classic is vulnerable to an incorrect authorization flaw that allows unauthenticated remote attackers to execute arbitrary code without user interaction.

Executive summary

A critical authorization vulnerability in Adobe Campaign Classic allows for unauthenticated remote code execution, posing an extreme risk to infrastructure integrity.

Vulnerability

This vulnerability, categorized as CWE-863, involves an incorrect authorization mechanism that fails to validate user privileges, permitting unauthenticated attackers to execute arbitrary code.

Business impact

The exploitation of this flaw leads to a complete compromise of the affected system, as indicated by the CVSS score of 10.0. Successful attacks result in total loss of confidentiality, integrity, and availability, potentially allowing unauthorized actors to move laterally within the network or exfiltrate sensitive customer data.

Remediation

Immediate Action: Upgrade Adobe Campaign Classic to ACC v7: 7.4.4 build 9400 or later to resolve the authorization failure.

Proactive Monitoring: Inspect server logs for suspicious API calls or unauthorized access requests originating from external IP addresses.

Compensating Controls: Deploy a Web Application Firewall (WAF) to block malicious traffic patterns and restrict access to the Campaign interface to known, trusted management segments.

Exploitation status

Public Exploit Available: No (unknown)

Analyst recommendation

Given the critical nature of this vulnerability and the ease of exploitation, immediate patching is required. Organizations should prioritize updating their Adobe Campaign Classic installations to build 9400 to eliminate the risk of remote code execution.

More Adobe CVEs