Executive brief
Adobe Campaign Classic is a marketing automation platform used to design and execute campaigns. An authorization vulnerability allows attackers to execute arbitrary code in the application without authentication or user interaction, potentially compromising the entire marketing and customer data management system.
Technical details
An incorrect authorization check in Adobe Campaign Classic permits unauthenticated arbitrary code execution in the application context. The vulnerability does not require user interaction and results in scope change, indicating the attacker can operate beyond the vulnerable component's normal boundaries. A patch is available from Adobe.
Affected products
- Adobe Campaign Classic <UNKNOWN>
Timeline
- 2026-09-22: disclosed