Sceawere

Vulnerability Detail

CVE-2026-27302UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Adobe Campaign Classic Authorization Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
10
Creation Date
6h ago
Vendor
Adobe
Product
Adobe Campaign Classic
Attack Type
Incorrect Authorization (CWE-863)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "10.0",
  "pubDate": "2026-08-11T18:17:25.603Z",
  "pubdate": "2026-08-11T18:17:25.603Z",
  "executiveSummary": "Adobe Campaign Classic (ACC) suffers from an Incorrect Authorization vulnerability that permits unauthenticated or improperly authorized entities to achieve arbitrary code execution within the security context of the currently executing user. This security flaw introduces critical risk implications to enterprise environments deploying the affected product, potentially allowing malicious actors to compromise underlying host systems, manipulate application data, or pivot through connected network infrastructure.\nThe vulnerability presents a severe threat profile due to the absence of required user interaction for successful exploitation. Attackers possessing network access to vulnerable Adobe Campaign Classic instances can leverage this authorization flaw to bypass access control mechanisms and execute arbitrary code remotely. The scope of the vulnerability is classified as changed, indicating that a successful exploit impacts components or resources beyond the immediate security boundaries of the vulnerable application.\nOrganizations utilizing Adobe Campaign Classic must prioritize remediation efforts by applying official vendor patches as soon as they become available. Given the lack of required user interaction and the potential for arbitrary code execution, this vulnerability demands immediate attention from security operations and vulnerability management teams to mitigate potential exploitation vectors.",
  "technicalDetails": "The identified vulnerability resides within Adobe Campaign Classic (ACC) and stems from insufficient or flawed authorization checks governing critical application functionalities. Specifically, the root cause is an Incorrect Authorization flaw where the application fails to adequately validate whether a requesting entity possesses the necessary privileges to execute sensitive operations or invoke underlying system methods.\nBecause exploitation does not require user interaction, an attacker can directly target exposed interfaces or endpoints associated with the vulnerable component. The attack flow typically begins with reconnaissance to identify an accessible Adobe Campaign Classic deployment. Following target identification, the adversary constructs a crafted request designed to bypass the weak authorization checks implemented within the access control logic of the application.\nUpon transmission of the malicious payload to the vulnerable endpoint, the application processes the request without enforcing proper privilege validation. This improper handling allows the attacker to interact with backend functions in an unintended manner. By chaining this authorization bypass with system-level interactions or insecure deserialization/execution primitives accessible to the application process, the attacker achieves arbitrary code execution.\nThe execution of arbitrary code occurs directly within the execution context of the user running the Adobe Campaign Classic service or process. Depending on how the service is deployed and configured, this could range from a standard user account to elevated privileges, thereby dictating the immediate post-exploitation impact on the host operating system. The scope is changed, highlighting that the consequences extend past the application layer to potentially affect host integrity and adjacent resources accessible via the service context.\nNetwork exposure is a prerequisite for remote exploitation, requiring connectivity to the exposed services of Adobe Campaign Classic. Authentication and privilege requirements are bypassed entirely or partially due to the authorization flaw, enabling unauthorized entities to perform actions reserved for trusted users or administrators. Post-exploitation activities could include establishing persistent access, exfiltrating sensitive marketing databases, deploying secondary payloads, or utilizing the compromised host as a staging point for internal network reconnaissance."
}
CVE-2026-27302: Adobe Campaign Classic Authorization Vulnerability (CRITICAL Severity, CVSS: 10.0) - Sceawere