Incorrect Authorization Vulnerability in Adobe Campaign Classic
CVE-2026-27302

10CRITICAL

Key Information:

Vendor

Adobe

Vendor
CVE Published:
11 August 2026

What is CVE-2026-27302?

Adobe Campaign Classic is susceptible to an Incorrect Authorization vulnerability that allows an attacker to execute arbitrary code with the permissions of the current user. This exploitation does not necessitate user interaction, leading to potential misuse of system functionalities. The issue arises from insufficient checks on user permissions, thereby altering the intended scope of access.

Affected Version(s)

Adobe Campaign Classic 0

Adobe Campaign Classic 0

Adobe Campaign Classic ACC v7: 7.4.4 build 9400

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.