Server-Side Request Forgery in Adobe Campaign Classic Affects Multiple Versions
CVE-2026-47938

10CRITICAL

Key Information:

Vendor

Adobe

Vendor
CVE Published:
9 June 2026

What is CVE-2026-47938?

Adobe Campaign Classic versions 7.4.3 build 9394 and earlier are vulnerable to a Server-Side Request Forgery (SSRF) issue that allows attackers to manipulate server requests. This flaw can be exploited without user interaction, resulting in potential unauthorized access and privilege escalation within the system.

Affected Version(s)

Adobe Campaign Classic (ACC) 0 <= 7.4.3 build 9394

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.