Adobe Campaign Classic Incorrect Authorization RCE
First seen Aug 12, 2026 · Updated Aug 12, 2026 · CVSS 10
A critical Incorrect Authorization vulnerability in Adobe Campaign Classic (ACC) allows attackers to achieve arbitrary code execution in the context of the current user without any user interaction. With a CVSS score of 10.0 and a changed scope, successful exploitation could lead to full compromise of the marketing automation platform and downstream systems it integrates with.
Technical Analysis
CVE-2026-71398 stems from improper authorization checks within Adobe Campaign Classic, enabling an attacker to bypass access controls and execute arbitrary code in the context of the current user. The lack of required user interaction combined with a changed scope (CVSS 10.0) suggests the flaw allows an unauthenticated or low-privilege actor to escalate impact beyond the vulnerable component itself, potentially affecting connected data stores, credential vaults, or downstream marketing/CRM integrations. Given ACC's role in orchestrating customer data workflows, exploitation could enable data exfiltration, lateral movement, or persistent backdoor deployment. Organizations that integrate AI agents or LLM-based tools with Campaign Classic for automated content generation, customer segmentation, or campaign orchestration should treat this as agent-relevant, since a compromised ACC instance could leak API keys, customer PII, or manipulate agent-driven workflows that consume campaign data.
Affected Systems
Adobe Campaign Classic (ACC) - specific vulnerable version range not disclosed in source data; organizations should consult Adobe's security bulletin for exact affected versions and apply patches accordingly
Indicators of Compromise
- No specific IOCs published at this time; monitor Adobe Security Bulletins and threat intelligence feeds for indicators as exploitation attempts emerge
Remediation Steps
- 1
Apply Adobe Security Patch
Immediately apply the official patch or update released by Adobe for Campaign Classic addressing CVE-2026-71398.
- 2
Restrict Network Access
Limit access to ACC management interfaces to trusted internal networks or VPN, reducing external attack surface.
- 3
Audit Authorization Controls
Review and harden role-based access control configurations within ACC to ensure least-privilege enforcement.
- 4
Monitor for Exploitation
Deploy monitoring for anomalous authentication events, unexpected code execution, or unusual outbound connections from ACC servers.
- 5
Rotate Credentials and API Keys
Rotate any API keys, service account credentials, or integration secrets tied to ACC, especially those used by connected automation or AI agent systems.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.