Junglewise Threat Intelligence

CVE-2026-82013: Adobe Campaign Classic Server-Side Request Forgery privilege escalation

CVE-2026-82013 · Severity: critical · CVSS 9.9 · Published 2026-09-22

Technologies: Microsoft Windows, Adobe Campaign Classic, Linux Kernel. Vendors: Microsoft, Adobe, Linux.

Executive brief

Adobe Campaign Classic, a marketing automation platform, contains a Server-Side Request Forgery vulnerability that allows low-privileged attackers to access internal resources and escalate their privileges without user interaction. An attacker could exploit this to gain unauthorized administrative access to the system and its data, posing a significant risk to customer information and campaign management operations.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability in Adobe Campaign Classic permits low-privileged authenticated users to make arbitrary requests to internal resources, leading to privilege escalation. The vulnerability requires no user interaction and changes the scope of access within the system. A working exploit or patch status is not confirmed from the available information.

Affected products

  • Adobe Campaign Classic

Timeline

  • 2026-09-22: disclosed

References

Related threats