Executive brief
Adobe Campaign Classic is a marketing and customer communication platform used to manage campaigns and customer interactions. An authorization flaw allows attackers to execute arbitrary code in the context of the current user without requiring user interaction, potentially compromising the confidentiality, integrity, and availability of customer data and campaign infrastructure.
Technical details
The vulnerability is an Incorrect Authorization flaw in Adobe Campaign Classic that bypasses access controls and enables arbitrary code execution. The attack vector is network-based and does not require user interaction or special privileges. An attacker can exploit this to run malicious code in the security context of the affected application, gaining full control over campaign data, customer records, and potentially lateral movement within the infrastructure. A patch is expected from Adobe; consult the APSB26-123 security bulletin for remediation details.
Affected products
- Adobe Campaign Classic <UNKNOWN>
Timeline
- 2026-08-11: disclosed