CVE-2026-82013

9.9

Adobe · Adobe Campaign Classic

Adobe Campaign Classic is vulnerable to Server-Side Request Forgery, allowing low-privileged attackers to escalate privileges and access sensitive internal network resources.

Executive summary

A critical Server-Side Request Forgery vulnerability in Adobe Campaign Classic allows authenticated attackers to escalate privileges and compromise internal network infrastructure.

Vulnerability

The software is susceptible to a Server-Side Request Forgery (CWE-918) vulnerability that can be triggered by a low-privileged authenticated user. This flaw enables an attacker to force the application to interact with internal resources, facilitating privilege escalation and unauthorized access to systems beyond the application boundary.

Business impact

The vulnerability carries a CVSS score of 9.9, reflecting its critical potential for full system compromise. Successful exploitation allows an attacker to bypass internal network security controls, potentially leading to the exfiltration of sensitive data, unauthorized administrative actions, or the compromise of backend infrastructure. The resulting scope change significantly increases the blast radius of this vulnerability.

Remediation

Immediate Action: Update Adobe Campaign Classic to build 9402 or later as documented in the vendor security advisory.

Proactive Monitoring: Review application access logs for unusual outbound requests from the Campaign Classic server to internal subnets or sensitive infrastructure endpoints.

Compensating Controls: Implement strict egress filtering on the application server to restrict network connections to only known, required destinations, effectively neutralizing the SSRF vector.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the critical nature of this vulnerability and its potential for full system compromise, administrators must prioritize patching Adobe Campaign Classic to build 9402 immediately. Organizations unable to patch instantly should verify that network segmentation and egress controls are strictly enforced to prevent the application from communicating with unauthorized internal resources.

More Adobe CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources