criticalZero-Day

Adobe Campaign Classic Incorrect Authorization RCE

First seen Aug 12, 2026 · Updated Aug 12, 2026 · CVSS 10

adobecampaign-classicrceauthorization-bypassunauthenticatedmarketing-platform

A critical Incorrect Authorization vulnerability in Adobe Campaign Classic (ACC) allows attackers to achieve arbitrary code execution in the context of the current user without any user interaction. With a CVSS score of 10.0 and a changed scope, successful exploitation could lead to full compromise of the marketing automation platform and downstream systems it integrates with.

Technical Analysis

CVE-2026-71398 stems from improper authorization checks within Adobe Campaign Classic, enabling an attacker to bypass access controls and execute arbitrary code in the context of the current user. The lack of required user interaction combined with a changed scope (CVSS 10.0) suggests the flaw allows an unauthenticated or low-privilege actor to escalate impact beyond the vulnerable component itself, potentially affecting connected data stores, credential vaults, or downstream marketing/CRM integrations. Given ACC's role in orchestrating customer data workflows, exploitation could enable data exfiltration, lateral movement, or persistent backdoor deployment. Organizations that integrate AI agents or LLM-based tools with Campaign Classic for automated content generation, customer segmentation, or campaign orchestration should treat this as agent-relevant, since a compromised ACC instance could leak API keys, customer PII, or manipulate agent-driven workflows that consume campaign data.

Affected Systems

Adobe Campaign Classic (ACC) - specific vulnerable version range not disclosed in source data; organizations should consult Adobe's security bulletin for exact affected versions and apply patches accordingly

Indicators of Compromise

  • No specific IOCs published at this time; monitor Adobe Security Bulletins and threat intelligence feeds for indicators as exploitation attempts emerge

Remediation Steps

  1. 1

    Apply Adobe Security Patch

    Immediately apply the official patch or update released by Adobe for Campaign Classic addressing CVE-2026-71398.

  2. 2

    Restrict Network Access

    Limit access to ACC management interfaces to trusted internal networks or VPN, reducing external attack surface.

  3. 3

    Audit Authorization Controls

    Review and harden role-based access control configurations within ACC to ensure least-privilege enforcement.

  4. 4

    Monitor for Exploitation

    Deploy monitoring for anomalous authentication events, unexpected code execution, or unusual outbound connections from ACC servers.

  5. 5

    Rotate Credentials and API Keys

    Rotate any API keys, service account credentials, or integration secrets tied to ACC, especially those used by connected automation or AI agent systems.

CVE / Advisory IDs

CVE-2026-27302

Industries Most Exposed

Marketing and AdvertisingRetailFinancial ServicesTechnologyMedia and Entertainment

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.