Executive brief
Adobe Campaign Classic, a marketing automation platform, is affected by a critical security flaw. An attacker could exploit this vulnerability to gain full control over the system and execute malicious commands without any user interaction. This could lead to the complete compromise of customer data, marketing operations, and the underlying server infrastructure.
Technical details
Adobe Campaign Classic (ACC) is vulnerable to a Server-Side Request Forgery (SSRF) classified as CWE-918. The vulnerability exists in versions 7.4.3 build 9394 and earlier. An unauthenticated remote attacker can exploit this flaw over the network without any user interaction. Due to a change in scope (S:C), the SSRF can be leveraged to achieve arbitrary code execution in the context of the current user. Adobe has addressed this issue in security bulletin APSB26-66, and users are advised to update to the latest patched version.
Affected products
- Adobe Campaign Classic (ACC) 7.4.3 build 9394 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory