Executive brief
Adobe Campaign Classic, a marketing automation platform, contains a Server-Side Request Forgery vulnerability that allows low-privileged attackers to access internal resources and escalate their privileges without user interaction. An attacker could exploit this to gain unauthorized administrative access to the system and its data, posing a significant risk to customer information and campaign management operations.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability in Adobe Campaign Classic permits low-privileged authenticated users to make arbitrary requests to internal resources, leading to privilege escalation. The vulnerability requires no user interaction and changes the scope of access within the system. A working exploit or patch status is not confirmed from the available information.
Affected products
- Adobe Campaign Classic
Timeline
- 2026-09-22: disclosed