Executive brief
Adobe Campaign Classic, an enterprise marketing automation platform, contains an authorization flaw that allows attackers to execute arbitrary code with the privileges of the affected user. An attacker can exploit this vulnerability remotely without requiring any user interaction, potentially gaining complete control over the campaign system and access to sensitive marketing data.
Technical details
An incorrect authorization vulnerability in Adobe Campaign Classic permits unauthenticated or low-privileged attackers to bypass access controls and execute arbitrary code in the context of the current user. The vulnerability is exploitable over the network without user interaction or additional prerequisites, allowing remote code execution with application-level privileges.
Affected products
- Adobe Campaign Classic
Timeline
- 2026-09-22: disclosed