CVE-2026-76195
10.0Adobe · Campaign Classic
Adobe Campaign Classic is affected by an OS Command Injection vulnerability that permits unauthenticated remote attackers to execute arbitrary code on the underlying host.
Executive summary
Adobe Campaign Classic contains a critical OS Command Injection flaw, allowing unauthenticated remote attackers to execute arbitrary code with the privileges of the application.
Vulnerability
This is an OS Command Injection (CWE-78) vulnerability. The attack vector is network-based and does not require authentication or user interaction.
Business impact
With a CVSS score of 10.0, this vulnerability represents an extreme risk to organizational security. An attacker can gain total control of the server, leading to potential lateral movement, data exfiltration, and full operational failure of the affected Adobe Campaign instance.
Remediation
Immediate Action: Apply the vendor-supplied update to ACC v7 build 9401 or later without delay.
Proactive Monitoring: Monitor system logs for unusual process execution or unexpected shell commands initiated by the application service user.
Compensating Controls: Utilize a Web Application Firewall (WAF) to detect and block malicious payloads containing command injection sequences before they reach the application.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this command injection vulnerability necessitates immediate patching. Security teams must ensure all instances of Adobe Campaign Classic are updated to build 9401 to prevent potential remote code execution by unauthenticated actors.