Critical Adobe Campaign Classic Flaws Let Attackers Run Code
Key Takeaways Adobe has released a critical security update for its Campaign Classic product, addressing multiple severe vulnerabilities. The flaws, which include several rated 10.0 on the CVSS...
Key Takeaways
- Adobe has released a critical security update for its Campaign Classic product, addressing multiple severe vulnerabilities.
- The flaws, which include several rated 10.0 on the CVSS scale, could allow unauthenticated remote code execution.
- All versions of Adobe Campaign Classic ACC v7.4.3 build 9398 and earlier on both Windows and Linux are affected.
- Organizations utilizing on-premise or hybrid deployments must upgrade to ACC v7.4.3 build 9399 immediately. Adobe-hosted instances have already been patched.
Adobe has issued an urgent security bulletin, APSB26-120, to address a series of critical vulnerabilities within Adobe Campaign Classic. Published on August 3, 2026, the update carries Adobe’s highest priority rating, underscoring the severe risk these flaws pose. Successful exploitation could lead to arbitrary code execution on affected systems.
Table Of Content
The vulnerabilities impact Adobe Campaign Classic (ACC) v7.4.3 build 9398 and earlier versions, running on both Windows and Linux environments. Businesses are strongly advised to upgrade their installations to ACC v7.4.3 build 9399 without delay.
Adobe Campaign Classic is a vital tool for organizations, enabling them to manage complex cross-channel marketing campaigns, maintain customer profiles, automate email workflows, and streamline campaign operations. A compromise of this system could expose highly sensitive marketing data, internal infrastructure details, confidential customer information, and potentially impact interconnected systems.
Adobe Campaign Classic Vulnerabilities
Critical Remote Code Execution Flaws
The most severe issues identified are three unauthenticated remote vulnerabilities, each scoring a perfect 10.0 on the CVSS scale, that allow for arbitrary code execution. These include:
- CVE-2026-48331: A Server-Side Request Forgery (SSRF) vulnerability.
- CVE-2026-48323: A template engine injection flaw.
- CVE-2026-48330: An SQL injection vulnerability.
The CVSS vectors for these flaws highlight their extreme danger: attackers can exploit them remotely over a network without needing any authentication or user interaction. This makes externally accessible or internet-facing Campaign Classic deployments particularly vulnerable and necessitates immediate patching.
Specifically, CVE-2026-48331, the SSRF vulnerability, could permit an attacker to force the vulnerable server to make requests to internal services, cloud metadata endpoints, or other systems typically inaccessible from the internet. In certain configurations, this could facilitate credential theft, internal network mapping, or access to administrative services.
Additional High-Severity Vulnerabilities
Beyond the critical 10.0 flaws, Adobe also patched CVE-2026-48326, another SQL injection vulnerability rated 9.9 out of 10. While this particular flaw requires low-level privileges for exploitation, an authenticated malicious user or an attacker leveraging stolen credentials could still exploit it to execute code and compromise the underlying server.
CVE-2026-48333, with a CVSS score of 9.8, addresses an incorrect authorization vulnerability that could lead to privilege escalation. Such flaws can be exploited by attackers to gain access to functions or data beyond their authorized permissions.
Other significant issues resolved include CVE-2026-48317, an eval injection vulnerability scoring 9.6, and CVE-2026-48399, a security feature bypass flaw rated 7.5. Eval injection vulnerabilities typically arise from unsafe processing of dynamic code, potentially allowing attackers to execute arbitrary commands.
Adobe has stated that it is currently unaware of any active exploits targeting these vulnerabilities in the wild. However, the combination of their critical severity, remote attack vectors, and the absence of authentication requirements makes swift remediation absolutely essential for all affected organizations. The Adobe bulletin applies to on-premise and hybrid Adobe Campaign Classic deployments. Customers using Adobe-hosted instances do not need to take action, as these environments have already been remediated by Adobe.
What You Should Do
- Immediately identify all exposed Adobe Campaign Classic servers within your infrastructure.
- Apply the update to ACC v7.4.3 build 9399 on all affected Windows and Linux systems as soon as possible.
- Review and audit all administrative accounts for Adobe Campaign Classic, ensuring strong passwords and least privilege principles.
- Restrict unnecessary network access to Campaign Classic deployments, especially for internet-facing instances.
- Monitor system logs diligently for any unusual requests, unexpected database activity, or suspicious changes in user privileges.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.