A critical security vulnerability (CVE-2026-27302) has been disclosed in Adobe Campaign Classic (ACC) and Adobe Campaign software. The flaw stems from an incorrect authorization mechanism that could enable attackers to execute arbitrary code in the context of the current user. This vulnerability does not require user interaction for exploitation, significantly increasing its risk profile. The CVSS score of 10.0 reflects the highest severity due to the potential for remote code execution with no barriers to exploitation. Organizations utilizing affected versions of Adobe Campaign Classic or Adobe Campaign are advised to apply vendor-provided patches immediately. Attackers could leverage this flaw to compromise systems, escalate privileges, or deploy malicious payloads. Mitigation steps include restricting network access to affected systems, implementing strict access controls, and monitoring for anomalous activity. Adobe has released updates to address this issue. Users should verify their software versions and follow official guidance for remediation. Given the critical impact and ease of exploitation, urgent action is required to prevent potential large-scale compromises.
CRITICAL
CVSS 10.0
CVE-2026-27302
2026-08-18
Critical Vulnerability in Adobe Campaign Products Allows Arbitrary Code Execution (CVE-2026-27302)
A critical vulnerability (CVSS 10.0) in Adobe Campaign Classic and Adobe Campaign allows arbitrary code execution due to incorrect authorization. Exploitation requires no user interaction. Immediate patching is strongly recommended.