Adobe Campaign Classic OS Command Injection (CVE-2026-76197)
First seen Aug 27, 2026 · Updated Aug 27, 2026 · CVSS 10
A critical OS command injection vulnerability in Adobe Campaign Classic (CVE-2026-76197) allows attackers to achieve arbitrary code execution without requiring user interaction, and carries a maximum CVSS score of 10.0. Organizations running ACC for marketing automation should treat this as an urgent patching priority given the scope change and lack of required authentication or interaction.
Technical Analysis
CVE-2026-76197 stems from improper neutralization of special elements used in OS commands, enabling an attacker to inject and execute arbitrary OS-level commands in the context of the current running user. The vulnerability's 'Scope changed' designation indicates the exploited component can impact resources beyond its own security scope, increasing the blast radius of a successful attack. No user interaction is required, suggesting the flaw is likely reachable via a network-facing interface or API endpoint exposed by ACC, making it attractive for automated exploitation and worming. Given the maximum CVSS score of 10.0, this is functionally equivalent to a pre-auth RCE and should be assumed exploitable at internet scale once technical details or PoC code circulate. If Adobe Campaign Classic instances are integrated with AI agent or automation pipelines (e.g., agents that trigger marketing workflows, pull customer data, or use ACC APIs as a tool), a successful command injection could allow attackers to pivot into agent orchestration environments, exfiltrate API keys/credentials used by agents, or manipulate agent-driven campaign data, so this qualifies as agent-relevant where such integrations exist.
Affected Systems
Adobe Campaign Classic (ACC) - specific vulnerable version ranges not disclosed in source data; organizations should consult Adobe's official security bulletin for exact affected builds and platform configurations (Windows/Linux server deployments).
Indicators of Compromise
- No specific IOCs (hashes, IPs, domains, file names) provided in source data at time of publication.
Remediation Steps
- 1
Apply Adobe Security Patch
Monitor Adobe's official security bulletin for CVE-2026-76197 and apply the patched version of Adobe Campaign Classic as soon as it is released.
- 2
Restrict Network Exposure
Limit direct internet exposure of ACC management interfaces and APIs; place them behind VPN, WAF, or IP allowlisting until patched.
- 3
Monitor for Exploitation
Review ACC server logs for anomalous command execution, unexpected child processes spawned by ACC service accounts, or unusual outbound connections.
- 4
Least Privilege Service Accounts
Ensure the ACC application runs with minimal OS-level privileges to limit the impact of a successful command injection.
- 5
Audit Agent/Automation Integrations
If AI agents or automation workflows interact with ACC APIs, rotate any credentials/API keys used and audit for unauthorized access following patch deployment.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.