CVE-2026-71398
Analyzed Analyzed - Analysis Complete

Incorrect Authorization in Adobe Campaign Classic Leads to Code Execution

Vulnerability report for CVE-2026-71398, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-28

Assigner: Adobe Systems Incorporated

Description

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-28
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-30
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
adobe campaign From 7.2.1 (inc) to 7.4.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Adobe Campaign Classic has an Incorrect Authorization vulnerability allowing attackers to execute arbitrary code without user interaction. This occurs because the system fails to properly verify authorization before granting access.

Detection Guidance

Detection requires checking for unauthorized code execution attempts or unusual activity in Adobe Campaign Classic (ACC) logs. Monitor for unexpected user sessions or processes running with elevated privileges. Check network traffic for unusual outbound connections from ACC servers.

Impact Analysis

An attacker could exploit this to run malicious code on your system, potentially stealing data, installing malware, or taking control of affected machines. Since no user interaction is needed, attacks can happen silently.

Compliance Impact

This vulnerability could lead to unauthorized access, data breaches, or loss of sensitive data, violating GDPR and HIPAA requirements for data protection and access controls.

Mitigation Strategies

Apply the latest security patches from Adobe immediately. Restrict network access to ACC servers to trusted IPs only. Disable unnecessary services or user accounts. Enable detailed logging and monitor for suspicious activity. Consider isolating ACC servers from critical systems until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71398. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart