Executive brief
Adobe Campaign Classic, a marketing automation platform used for managing cross-channel customer campaigns, is affected by a critical security flaw. This vulnerability allows an attacker to remotely execute malicious commands on the system without any user interaction. Successful exploitation could lead to a total compromise of the server, potentially exposing sensitive customer data and disrupting marketing operations.
Technical details
Adobe Campaign Classic (ACC) contains an incorrect authorization vulnerability (CWE-863) in versions 7.4.3 build 9396 and earlier. The flaw allows a remote, unauthenticated attacker to bypass security checks and execute arbitrary code on the host system. The vulnerability is particularly severe because it requires no user interaction and results in a 'Scope Change' (S:C) under CVSS 3.1, indicating the impact can extend beyond the Adobe Campaign application to the underlying operating system or environment. Adobe has addressed this issue in security bulletin APSB26-69.
Affected products
- Adobe Campaign Classic (ACC) 7.4.3 build 9396 and earlier
Timeline
- 2026-06-30: disclosed
- 2026-06-30: advisory