ZeroHour

CVE-2026-27302

large

Unauthenticated Arbitrary Code Execution via Authorization Flaw in Adobe Campaign Classic

CVSS 3.1
10.0 critical
EPSS
<1%p51
Published
()
Modified
AI analysis

CVE-2026-27302 is an incorrect authorization flaw (CWE-863) in Adobe Campaign Classic (ACC) in which access controls are not properly enforced, allowing an attacker to trigger arbitrary code execution in the context of the application's user. Per the CVSS 3.1 vector, it is exploitable over a network with no privileges required and no user interaction, and the 'scope changed' designation means the code execution escapes the vulnerable component, extending impact beyond the application itself. A successful attacker gains arbitrary code execution on the affected server with high impact to confidentiality, integrity, and availability, reflected in the maximum 10.0 base score. Any organization running an affected version of Campaign Classic — an enterprise marketing campaign management platform — is exposed; exact affected version ranges are not included in the available data and must be confirmed in Adobe's advisory. There is no known public exploit or PoC, the flaw is not in CISA KEV, EPSS estimates a roughly 0.7% probability of exploitation within 30 days (51st percentile), and Adobe shipped the fix in a batch release that also addressed two other CVSS 10.0 flaws in ColdFusion and Campaign Classic.

What to do: Update Adobe Campaign Classic to the release specified in Adobe's security advisory, prioritizing internet-exposed instances since exploitation requires no authentication or user interaction. Until patched, restrict network access to Campaign Classic application servers and monitor for anomalous process activity. Because affected version ranges are not in this dataset, verify eligibility against the advisory before scheduling the upgrade.

Affected
Adobe Campaign Classic (ACC)
Estimated exposure
large≈10,000–100,000 enterprise users/instances (thousands of enterprise deployments; Adobe publishes no active-install counts) — Campaign Classic is an enterprise marketing automation platform sold to large organizations that typically run a handful of server instances per customer, so the deployed base plausibly falls in the tens of thousands of users/instances;…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Vendors
adobe
Products
campaign
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Adobe patches seven flaws in ColdFusion, Commerce, and Campaign Classic, including actively exploited CVE-2026-71362 enabling customer account takeover.

Adobe issued Priority 1 updates fixing CVSS 10.0 flaws in ColdFusion (CVE-2026-48362, OS command injection) and Campaign Classic (CVE-2026-71398, CVE-2026-27302, incorrect authorization), plus CVE-2026-71362 (CVSS 9.1) in Adobe Commerce and Magento Open Source. Sansec reports threat actors are actively exploiting CVE-2026-71362 to switch customer sessions to other accounts and access private customer data. Adobe-hosted Campaign Classic instances are already remediated, while on-premise deployments are urged to patch within 72 hours. ColdFusion fixes ship in versions 2025.0.12 and 2023.0.23, and Campaign Classic fixes in v7 7.4.4 build 9400.

The Hacker News · Aug 15, 2026Vulnerability in the wildCVE-2026-48362CVE-2026-48273CVE-2026-71384+5 CVEs