CVE-2026-75699

10.0

Adobe · Campaign Classic

Adobe Campaign Classic is vulnerable to code injection, allowing unauthenticated remote attackers to execute arbitrary code with the privileges of the application process.

Executive summary

Adobe Campaign Classic contains a critical code injection vulnerability that allows unauthenticated remote attackers to achieve full system compromise.

Vulnerability

This is an improper control of generation of code (CWE-94) vulnerability. It allows an unauthenticated, remote attacker to execute arbitrary code without requiring user interaction, resulting in a change of security scope.

Business impact

The ability for an unauthenticated attacker to execute arbitrary code on the host system poses an extreme risk to business operations. A successful exploit could lead to full data exfiltration, unauthorized modification of customer marketing campaigns, and complete compromise of the underlying server infrastructure, justifying the maximum CVSS score of 10.0.

Remediation

Immediate Action: Update Adobe Campaign Classic to build 9402 or later as specified in the vendor security advisory.

Proactive Monitoring: Monitor server access logs for suspicious inbound traffic or unexpected process execution patterns originating from the web application interface.

Compensating Controls: Deploy or update Web Application Firewall (WAF) rules to inspect and filter malicious payloads targeting code injection vectors while the patch is being applied.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability represents a critical risk to the organization due to the potential for unauthenticated remote code execution. Security teams must treat this as a high-priority patching task and ensure the environment is updated to build 9402 or higher immediately to prevent potential exploitation.

More Adobe CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources