CVE-2026-71398
10.0Adobe · Campaign Classic
Adobe Campaign Classic contains an incorrect authorization vulnerability that permits unauthenticated remote attackers to achieve arbitrary code execution.
Executive summary
A critical authorization vulnerability in Adobe Campaign Classic enables unauthenticated remote code execution, threatening the entire application environment.
Vulnerability
The software suffers from an incorrect authorization flaw (CWE-863) that allows an unauthenticated, remote attacker to bypass security controls and execute arbitrary code.
Business impact
With a CVSS score of 10.0, this vulnerability represents a maximum-severity risk. Successful exploitation grants an attacker full control over the application, leading to potential data breaches, unauthorized system modifications, and significant operational disruption.
Remediation
Immediate Action: Update Adobe Campaign Classic to ACC v7: 7.4.4 build 9400 immediately to apply the necessary authorization fixes.
Proactive Monitoring: Review system access logs for anomalous activity and monitor for unexpected service execution processes that may indicate exploitation attempts.
Compensating Controls: Implement strict network-level access controls to ensure the Campaign Classic interface is not exposed to the public internet.
Exploitation status
Public Exploit Available: No (unknown)
Analyst recommendation
The severity of this vulnerability necessitates immediate remediation. Security teams must ensure all instances of Adobe Campaign Classic are updated to the specified patch level to mitigate the risk of unauthorized remote code execution.