Junglewise Threat Intelligence

CVE-2026-75728: Adobe Campaign Classic authorization bypass leading to code execution

CVE-2026-75728 · Severity: critical · CVSS 9.1 · Published 2026-09-22

Technologies: Microsoft Windows, Linux Kernel, Adobe Campaign Classic. Vendors: Microsoft, Linux, Adobe.

Executive brief

Adobe Campaign Classic, an enterprise marketing automation platform, contains an authorization flaw that allows attackers to execute arbitrary code with the privileges of the affected user. An attacker can exploit this vulnerability remotely without requiring any user interaction, potentially gaining complete control over the campaign system and access to sensitive marketing data.

Technical details

An incorrect authorization vulnerability in Adobe Campaign Classic permits unauthenticated or low-privileged attackers to bypass access controls and execute arbitrary code in the context of the current user. The vulnerability is exploitable over the network without user interaction or additional prerequisites, allowing remote code execution with application-level privileges.

Affected products

  • Adobe Campaign Classic

Timeline

  • 2026-09-22: disclosed

References

Related threats