Executive brief
Adobe Campaign Classic, a marketing automation platform used for managing cross-channel customer campaigns, is affected by a critical security flaw. This vulnerability allows an attacker to execute unauthorized commands on the system without any user interaction. Successful exploitation could lead to a total compromise of the application, potentially exposing sensitive customer data and disrupting marketing operations.
Technical details
Adobe Campaign Classic (ACC) contains an incorrect authorization vulnerability (CWE-863) in versions 7.4.3 build 9394 and earlier. The flaw allows a remote, unauthenticated attacker to bypass authorization checks and achieve arbitrary code execution in the context of the current user. The vulnerability is particularly severe as it requires no user interaction and involves a scope change (S:C), indicating the impact may extend beyond the immediate software component. Adobe has addressed this issue in security bulletin APSB26-66.
Affected products
- Adobe Campaign Classic (ACC) 7.4.3 build 9394 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory