Sceawere

Vulnerability Detail

CVE-2026-76193UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Adobe Campaign Classic SSRF Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
10
Creation Date
1d ago
Vendor
Adobe
Product
Adobe Campaign Classic
Attack Type
Server-Side Request Forgery (SSRF) (CWE-918)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "10.0",
  "pubDate": "2026-08-25T18:18:04.813Z",
  "pubdate": "2026-08-25T18:18:04.813Z",
  "executiveSummary": "Adobe Campaign Classic (ACC) contains a Server-Side Request Forgery (SSRF) vulnerability that enables remote attackers to manipulate server-side requests. This flaw allows unauthorized interaction with internal resources or network services accessible to the application server. The vulnerability poses a significant security risk, as it can be leveraged to achieve arbitrary code execution within the context of the user running the Adobe Campaign Classic service. Successful exploitation does not require user interaction, meaning an attacker can trigger the malicious flow autonomously. The scope of this vulnerability is categorized as changed, indicating that the impact of the exploitation extends beyond the security boundaries of the target application, potentially compromising the underlying host environment. Given the potential for code execution and the lack of required user interaction, this vulnerability is considered a critical security concern that necessitates immediate attention to prevent unauthorized system control.",
  "technicalDetails": "The vulnerability resides in the request-handling logic of Adobe Campaign Classic, which fails to properly validate or sanitize user-supplied input before initiating outbound network requests. Server-Side Request Forgery occurs when an application processes a URI provided by an attacker, causing the server to fetch or interact with resources it should not otherwise access.\nRoot Cause Analysis: The internal architecture of Adobe Campaign Classic exposes functionality that permits the server to perform HTTP or other protocol-based requests to arbitrary destinations. Inadequate implementation of allow-listing or URI scheme validation allows an attacker to direct the server to communicate with internal network endpoints, metadata services (such as cloud instance identity endpoints), or local file system resources if supported by the protocol handler.\nExploitation Method and Attack Flow: An attacker exploits this by injecting a crafted payload into the vulnerable endpoint. Upon receiving the request, the Adobe Campaign Classic server-side component processes the malicious URI. The server then acts as a proxy, sending the request to the target destination. By manipulating the parameters, an attacker can bypass traditional network perimeter controls to reach internal services that are not exposed to the public internet.\nPost-Exploitation and Code Execution: The vulnerability is particularly severe because the SSRF can lead to arbitrary code execution. This typically occurs when the SSRF is used to target internal administrative interfaces, unauthenticated management APIs, or components that process deserialized data. If the attacker can influence the server to interact with these internal services, they may trigger secondary vulnerabilities (such as insecure deserialization or command injection) that escalate the SSRF into full code execution. Since the application runs with the privileges of the service user, the attacker inherits those permissions, potentially allowing for complete system compromise.\nEnvironmental Factors: The vulnerability does not require authentication or user interaction. Exploitation is performed via the network, targeting exposed application interfaces. The 'Scope Changed' classification reflects that the successful exploitation of the SSRF in Adobe Campaign Classic allows the attacker to influence components or environments beyond the direct scope of the application, such as the host OS or internal network segments."
}
CVE-2026-76193: Adobe Campaign Classic SSRF Vulnerability (CRITICAL Severity, CVSS: 10.0) - Sceawere