CVE-2026-76193

10.0

Adobe · Campaign Classic

Adobe Campaign Classic is vulnerable to a Server-Side Request Forgery (SSRF) flaw, which allows unauthenticated remote attackers to achieve arbitrary code execution.

Executive summary

Adobe Campaign Classic is susceptible to a critical SSRF vulnerability that enables unauthenticated remote code execution, posing a severe risk to system integrity.

Vulnerability

This is a Server-Side Request Forgery (CWE-918) vulnerability. The flaw is exploitable by an unauthenticated attacker over the network, requiring no user interaction.

Business impact

The CVSS score of 10.0 reflects the maximum severity, as this vulnerability provides an unauthenticated attacker with full control over the application. Successful exploitation could lead to total system compromise, unauthorized data access, and significant operational disruption.

Remediation

Immediate Action: Update Adobe Campaign Classic to ACC v7 build 9401 or later immediately.

Proactive Monitoring: Review web server and application access logs for suspicious outbound requests or unusual patterns originating from the Campaign Classic server.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block unauthorized server-side requests and restrict egress traffic from the application server to sensitive internal resources.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical nature of this vulnerability and the potential for full system compromise, organizations should prioritize patching Adobe Campaign Classic to build 9401. Immediate deployment of the update is required to eliminate this high-risk attack vector.

More Adobe CVEs