Junglewise Threat Intelligence

CVE-2026-47938: Adobe Campaign Classic SSRF leading to Remote Code Execution

CVE-2026-47938 · Severity: critical · CVSS 10 · Published 2026-06-09

Technologies: Adobe Campaign Classic. Vendors: Adobe.

Executive brief

Adobe Campaign Classic, a marketing automation platform, is affected by a critical security flaw. An attacker could exploit this vulnerability to gain full control over the system and execute malicious commands without any user interaction. This could lead to the complete compromise of customer data, marketing operations, and the underlying server infrastructure.

Technical details

Adobe Campaign Classic (ACC) is vulnerable to a Server-Side Request Forgery (SSRF) classified as CWE-918. The vulnerability exists in versions 7.4.3 build 9394 and earlier. An unauthenticated remote attacker can exploit this flaw over the network without any user interaction. Due to a change in scope (S:C), the SSRF can be leveraged to achieve arbitrary code execution in the context of the current user. Adobe has addressed this issue in security bulletin APSB26-66, and users are advised to update to the latest patched version.

Affected products

  • Adobe Campaign Classic (ACC) 7.4.3 build 9394 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats