CVE-2026-76197

10.0

Adobe · Campaign Classic

Adobe Campaign Classic is vulnerable to an OS Command Injection, allowing unauthenticated attackers to execute arbitrary code on the host system.

Executive summary

Adobe Campaign Classic is vulnerable to a critical OS Command Injection flaw, enabling unauthenticated attackers to execute arbitrary code and gain full control of the host system.

Vulnerability

This is an OS Command Injection (CWE-78) vulnerability. It is exploitable by unauthenticated remote attackers and does not require user interaction.

Business impact

The CVSS score of 10.0 indicates a maximum severity, highlighting the critical threat to business operations. Successful exploitation allows for complete system compromise, which can result in severe financial, reputational, and operational damage.

Remediation

Immediate Action: Update the affected Adobe Campaign Classic software to build 9401 or later.

Proactive Monitoring: Review system process logs for unauthorized or unexpected command execution patterns associated with the application environment.

Compensating Controls: Implement strict input validation at the WAF level to identify and filter out payloads that attempt to inject OS commands.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical CVSS rating, immediate remediation is essential. Administrators must verify that all Adobe Campaign Classic deployments are patched to build 9401 to mitigate the risk of remote code execution.

More Adobe CVEs