criticalOther

Adobe Campaign Classic Incorrect Authorization Leading to Arbitrary Code Execution

First seen Aug 13, 2026 · Updated Aug 13, 2026 · CVSS 10

adobeauthorization-bypassrcecvss10marketing-platformno-user-interaction

A critical Incorrect Authorization vulnerability in Adobe Campaign Classic (ACC) allows an unauthenticated attacker to execute arbitrary code in the context of the current user without any user interaction required. The maximum CVSS score of 10.0 and changed scope indicate the flaw can escalate impact beyond the vulnerable component itself, making this a top-priority patching target for any organization running ACC.

Technical Analysis

CVE-2026-71398 stems from improper authorization checks within Adobe Campaign Classic, permitting an attacker to bypass access controls and achieve arbitrary code execution in the context of the current user. The absence of a user-interaction requirement combined with a changed scope suggests the vulnerability likely enables lateral movement across process or trust boundaries, potentially compromising adjacent systems or session contexts. Given the CVSS score of 10.0, exploitation is likely network-based, low-complexity, and requires no privileges, making it highly attractive for mass exploitation once a PoC becomes public. Adobe Campaign Classic servers often integrate with CRM, marketing automation, and customer data pipelines; if any AI agents or LLM-based automation tools are integrated with ACC for content generation, customer segmentation, or campaign orchestration, a compromise here could expose API keys, customer PII, or allow injection of malicious instructions into automated workflows that agents consume, representing a plausible agent-relevant risk.

Affected Systems

Adobe Campaign Classic (ACC) - all deployments running vulnerable versions prior to the vendor-issued security patch; specific version ranges should be confirmed via the official Adobe Security Bulletin (APSB) for this CVE.

Indicators of Compromise

  • No specific IOCs published at this time; monitor Adobe Security Bulletin and threat intelligence feeds for indicators as exploitation develops.

Remediation Steps

  1. 1

    Apply Vendor Patch

    Immediately apply the official Adobe security update addressing CVE-2026-71398 as detailed in the corresponding Adobe Security Bulletin (APSB).

  2. 2

    Restrict Network Access

    Limit exposure of ACC management interfaces and application servers to trusted internal networks and VPNs until patched.

  3. 3

    Review Authorization Logs

    Audit ACC access logs for anomalous authorization attempts or privilege escalation activity predating the patch deployment.

  4. 4

    Rotate Integrated Credentials

    Rotate API keys, service account credentials, and tokens used by any integrated systems (including AI agents or automation pipelines) connected to ACC.

  5. 5

    Enable Monitoring and Alerting

    Deploy WAF rules and enhanced monitoring for exploitation attempts targeting authorization bypass patterns against ACC endpoints.

CVE / Advisory IDs

CVE-2026-71398

Industries Most Exposed

marketingretaile-commercemediatechnologyfinancial services

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.