Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed.
In-depth analysis on cveo.tech
We've published a detailed analysis of this CVE — exploitation, IOCs and mitigation.
CVSS v3.1 Score
9.6
/ 10.0
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Information
- Published
- 22 sept. 2026
- Updated
- 23 sept. 2026
- Status
- Analyzed
- Source
- psirt@adobe.com
Affected products
adobe campaign
Versions : 7.4.3, 7.4.4
Weaknesses (CWE)
CWE-918
References (1)
Similar CVEs
Other vulnerabilities of type CWE-918
Loading…
Monitor your products
Get automatic alerts for every new CVE affecting your equipment.