CVE-2026-83660
9.9Adobe · Adobe Campaign Classic
Adobe Campaign Classic is vulnerable to a Server-Side Request Forgery (SSRF) flaw that permits unauthenticated attackers to perform privilege escalation.
Executive summary
Adobe Campaign Classic is susceptible to a critical SSRF vulnerability that allows unauthenticated attackers to escalate privileges and potentially compromise system integrity.
Vulnerability
The application is affected by a Server-Side Request Forgery (CWE-918) vulnerability. Because the attack vector is network-based and requires no authentication or user interaction, an attacker can manipulate the server to perform unauthorized requests, leading to privilege escalation.
Business impact
Successful exploitation poses a severe risk to organizational infrastructure, as it allows unauthorized actors to bypass internal access controls. Given the CVSS score of 9.9, this vulnerability represents a critical threat capable of leading to unauthorized administrative access, sensitive data exposure, and potential compromise of the underlying server environment.
Remediation
Immediate Action: Update Adobe Campaign Classic to build 9402 or later as specified in the Adobe security advisory APSB26-142.
Proactive Monitoring: Monitor server access logs for unusual outbound requests originating from the Adobe Campaign application server to internal or restricted network endpoints.
Compensating Controls: Implement strict egress filtering on the firewall to prevent the application server from initiating connections to unauthorized internal network segments.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability is classified as critical due to the ease of exploitation and the potential for full privilege escalation. Administrators must prioritize applying the provided patch to build 9402 immediately to neutralize this threat, as unauthenticated access to the application server can lead to a total compromise of the affected environment.
More Adobe CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section