Adobe Campaign Classic (ACC) is vulnerable to a Server-Side Request Forgery (SSRF) flaw that enables attackers to execute unauthorized requests and escalate privileges. The vulnerability (CVE-2026-48331) has a CVSS score of 10.0, indicating the highest severity. Exploitation does not require user interaction, and the attack scope allows attackers to bypass intended security boundaries. This issue affects all versions of Adobe Campaign Classic. Successful exploitation could lead to unauthorized access, data exfiltration, or system compromise. Organizations using ACC are strongly advised to apply vendor-released patches immediately. Until patched, administrators should restrict network access to ACC instances and monitor for suspicious outbound requests. This vulnerability underscores the importance of timely updates for enterprise platforms exposed to untrusted inputs.
CRITICAL
CVSS 10.0
CVE-2026-48331
2026-08-16
Critical SSRF Vulnerability in Adobe Campaign Classic Allows Privilege Escalation (CVE-2026-48331)
A critical Server-Side Request Forgery (SSRF) vulnerability in Adobe Campaign Classic (ACC) allows attackers to escalate privileges without user interaction. With a CVSS score of 10.0, this issue requires immediate patching to prevent potential system compromise.