Sceawere

Vulnerability Detail

CVE-2026-75699UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Adobe Campaign Classic Code Injection

Vulnerability Metadata

Severity
Critical
Score / CVSS
10
Creation Date
2h ago
Vendor
Adobe
Product
Adobe Campaign Classic
Attack Type
Improper Control of Generation of Code ('Code Injection') (CWE-94)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "10.0",
  "pubDate": "2026-09-22T18:17:15.760Z",
  "pubdate": "2026-09-22T18:17:15.760Z",
  "executiveSummary": "Adobe Campaign Classic (ACC) is susceptible to an Improper Control of Generation of Code vulnerability, categorized as a code injection flaw.\nThis vulnerability allows an unauthenticated, remote attacker to execute arbitrary code within the security context of the current application user.\nThe flaw affects the integrity and confidentiality of the Adobe Campaign Classic environment, potentially leading to full system compromise.\nA notable characteristic of this vulnerability is that the scope is changed, indicating that the impact extends beyond the vulnerable component to other resources or security domains.\nSuccessful exploitation does not require user interaction, significantly increasing the risk factor as it enables automated or low-effort attacks.\nThe vulnerability highlights a critical failure in input validation or template processing mechanisms that allow the injection and subsequent execution of unauthorized code.\nOrganizations deploying Adobe Campaign Classic should prioritize addressing this vulnerability, as it provides an attacker with the capability to perform unauthorized operations, manipulate data, or pivot within the network infrastructure.",
  "technicalDetails": "The vulnerability resides within the Adobe Campaign Classic (ACC) framework and is classified as an Improper Control of Generation of Code (CWE-94). The root cause involves the application's failure to properly sanitize or constrain user-supplied input before it is processed by code generation engines or evaluation functions. This allows an attacker to inject arbitrary code segments that are subsequently executed by the server-side process.\nThe exploitation flow begins with the attacker crafting a malicious payload specifically designed to interact with the vulnerable code generation component. By sending this payload via the network, the attacker bypasses standard input controls. Because the vulnerability does not require prior authentication or user interaction, the attacker can transmit this payload directly to the target ACC instance. Once received, the application process interprets the malicious input as legitimate executable code, causing the server to execute the attacker's commands within its own process space.\nThe execution happens under the security context of the current user account running the Adobe Campaign Classic service. Consequently, the attacker inherits the permissions associated with this service account. If the service is running with high-level privileges, the impact of the arbitrary code execution is amplified, potentially granting the attacker complete control over the affected server instance. Furthermore, the 'Scope is changed' designation confirms that an attacker can influence resources outside the immediate application boundary, potentially facilitating lateral movement within the enterprise network.\nPost-exploitation activities are limited only by the privileges of the affected service account. An attacker may deploy web shells, exfiltrate sensitive campaign data, modify databases, or establish persistence mechanisms to maintain long-term access. Given the nature of code injection in this context, the payloads may be highly dynamic and difficult to detect without deep packet inspection and robust endpoint detection and response (EDR) solutions configured to monitor for anomalous process spawns from the Adobe Campaign process tree.\nThe vulnerability is inherent to the logic handling of the application's internal generation mechanisms, and any instance of Adobe Campaign Classic not shielded by updated security configurations or appropriate compensating controls is theoretically at risk."
}
CVE-2026-75699: Adobe Campaign Classic Code Injection (CRITICAL Severity, CVSS: 10.0) | Sceawere