ZeroHour

CVE-2026-71398

niche

Unauthenticated RCE in Adobe Campaign Classic via Incorrect Authorization

CVSS 3.1
10.0 critical
EPSS
<1%p54
Published
()
Modified
AI analysis

Adobe Campaign Classic contains an incorrect authorization flaw (CWE-863) that allows an unauthenticated remote attacker to execute arbitrary code in the context of the current user. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:C) indicates the flaw is reachable over the network with no privileges and no user interaction, and the changed scope shows the executed code crosses a security boundary, meaning a request to a vulnerable Campaign Classic instance can lead to code running beyond the application layer. A successful attacker gains code execution with high impact to confidentiality, integrity, and availability on the affected server. Organizations running Adobe Campaign Classic — typically large enterprises operating on-premises or hybrid marketing infrastructure — are affected; the available data does not specify affected version ranges, so defenders should consult the Adobe security bulletin for exact builds. There is currently no evidence of in-the-wild exploitation, no known public proof-of-concept, and the flaw is not in CISA's KEV; EPSS assigns a 0.8% probability of exploitation within 30 days (54th percentile).

What to do: Patch Campaign Classic to the fixed release identified in the Adobe security bulletin for this CVE, verifying the exact affected and fixed builds there since version ranges were not included in this data. Until patched, restrict network access to Campaign Classic servers from untrusted networks and review application and system logs for unexpected process or command execution. If your instances are hosted or managed by Adobe, confirm with Adobe that hosted environments have already been remediated.

Affected
Adobe Campaign Classic
Estimated exposure
nichelikely hundreds to low thousands of server instances across enterprise deployments (no public install-count data) — Adobe Campaign Classic is enterprise marketing software deployed per large organization (on-premises, hybrid, or Adobe-managed cloud) rather than a mass-market product, so only a limited number of customer-managed instances plausibly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Vendors
adobe
Products
campaign
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Adobe patches seven flaws in ColdFusion, Commerce, and Campaign Classic, including actively exploited CVE-2026-71362 enabling customer account takeover.

Adobe issued Priority 1 updates fixing CVSS 10.0 flaws in ColdFusion (CVE-2026-48362, OS command injection) and Campaign Classic (CVE-2026-71398, CVE-2026-27302, incorrect authorization), plus CVE-2026-71362 (CVSS 9.1) in Adobe Commerce and Magento Open Source. Sansec reports threat actors are actively exploiting CVE-2026-71362 to switch customer sessions to other accounts and access private customer data. Adobe-hosted Campaign Classic instances are already remediated, while on-premise deployments are urged to patch within 72 hours. ColdFusion fixes ship in versions 2025.0.12 and 2023.0.23, and Campaign Classic fixes in v7 7.4.4 build 9400.

The Hacker News · Aug 15, 2026Vulnerability in the wildCVE-2026-48362CVE-2026-48273CVE-2026-71384+5 CVEs