Junglewise Threat Intelligence

CVE-2026-71398: Adobe Campaign Classic authorization bypass leading to code execution

CVE-2026-71398 · Severity: critical · CVSS 10 · Published 2026-08-11

Technologies: Adobe Campaign Classic. Vendors: Adobe.

Executive brief

Adobe Campaign Classic is a marketing automation and customer relationship management platform used by enterprises to manage customer data and campaigns. An incorrect authorization vulnerability allows attackers to execute arbitrary code in the context of the application without requiring user interaction, potentially leading to unauthorized data access, system compromise, and operational disruption.

Technical details

The vulnerability is an incorrect authorization flaw in Adobe Campaign Classic that allows arbitrary code execution. The issue affects the application's authorization controls, permitting attackers to bypass authentication or permission checks and execute arbitrary code in the context of the current user or application context. No user interaction is required for exploitation, and the scope is changed, indicating the attacker can affect resources beyond the vulnerable component. Patches are expected to be available through Adobe's security bulletins.

Affected products

  • Adobe Campaign Classic <UNKNOWN>

Timeline

  • 2026-08-11: disclosed

References

Related threats