CVE-2026-48331

Adobe · Campaign Classic

Adobe Campaign Classic is affected by a Server-Side Request Forgery (SSRF) vulnerability that enables unauthenticated attackers to escalate privileges.

Executive summary

A critical Server-Side Request Forgery vulnerability in Adobe Campaign Classic permits unauthenticated remote attackers to escalate privileges and compromise the application.

Vulnerability

The application is susceptible to Server-Side Request Forgery (CWE-918), allowing an unauthenticated attacker to make unauthorized requests to internal resources. This manipulation can be leveraged to escalate privileges within the application environment.

Business impact

Successful exploitation allows an attacker to bypass security boundaries, potentially gaining administrative control over the Adobe Campaign instance. This undermines the security posture of the entire application and may provide a foothold for further network exploitation. The CVSS score of 10.0 reflects the critical nature of this vulnerability in an enterprise environment.

Remediation

Immediate Action: Apply the vendor-supplied update to Adobe Campaign Classic version 7.4.3 build 9399 or later.

Proactive Monitoring: Review server logs for anomalous outbound requests to internal metadata services or restricted network segments.

Compensating Controls: Utilize network segmentation to restrict the ability of the Adobe Campaign server to initiate connections to sensitive internal endpoints.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this SSRF vulnerability necessitates an immediate response. IT administrators should verify their current build version and apply the mandatory update to prevent unauthorized privilege escalation and potential system takeover.