Executive brief
Adobe Campaign Classic, a marketing automation platform used for managing cross-channel customer campaigns, is affected by a critical security flaw. This vulnerability allows an unauthorized attacker to remotely execute malicious code on the system without any user interaction. Successful exploitation could lead to a total compromise of the server, including the theft of sensitive customer data and disruption of marketing operations.
Technical details
Adobe Campaign Classic (ACC) contains an incorrect authorization vulnerability (CWE-863) that allows for remote code execution. The flaw is reachable over the network without authentication (AV:N/PR:N) and requires no user interaction (UI:N). Because the vulnerability results in a scope change (S:C), an attacker can potentially escape the application context to impact the underlying host system. The issue is resolved in Adobe Campaign Classic version 7.4.3 build 9398.
Affected products
- Adobe Campaign Classic (ACC) <= 7.4.3 build 9397
Timeline
- 2026-07-30: disclosed
- 2026-07-30: advisory