CVE-2026-75723

10.0

Adobe · Adobe Campaign Classic

Adobe Campaign Classic contains an Incorrect Authorization vulnerability allowing unauthenticated remote code execution. No user interaction is required for successful exploitation.

Executive summary

Adobe Campaign Classic is vulnerable to unauthenticated remote code execution, presenting a critical risk to system integrity and data confidentiality.

Vulnerability

This vulnerability stems from an incorrect authorization flaw (CWE-863) that allows an unauthenticated attacker to execute arbitrary code on the host system. The attack vector is network-based and requires no user interaction, making it highly automatable.

Business impact

The potential impact of this vulnerability is total system compromise, including the loss of confidentiality, integrity, and availability of sensitive data managed by the Adobe Campaign environment. With a CVSS score of 10.0, this is a critical severity issue that could lead to unauthorized access to customer databases or the deployment of persistent malware within the enterprise network.

Remediation

Immediate Action: Update Adobe Campaign Classic to build 9402 or higher immediately to apply the vendor-supplied security fix.

Proactive Monitoring: Review web server and application logs for anomalous requests, unexpected process execution, or unauthorized attempts to access administrative endpoints.

Compensating Controls: Implement strict network segmentation and egress filtering to limit the reach of an attacker, and utilize a Web Application Firewall (WAF) to detect and block malicious payloads targeting application authorization mechanisms.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the critical CVSS score of 10.0 and the potential for full remote code execution, organizations should prioritize this update above all other routine maintenance. Failure to patch this vulnerability leaves the application exposed to trivial exploitation by remote attackers. Ensure that the update to build 9402 is tested in a staging environment and deployed to production as soon as possible.

More Adobe CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources