External risk intelligence

Adobe Campaign Classic Incorrect Authorization Vulnerability Allows Code Execution

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-27302

Adobe Campaign Classic is an enterprise marketing and campaign management platform that is commonly deployed as a web-accessible application to manage customer data, external communications, and web-based marketing workflows, making it a frequent candidate for network-reachable or public-facing service deployments.

Adobe Campaign

7.2.1 to before 7.4.4

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

Adobe Campaign Classic is impacted by an authorization flaw that may permit attackers to run unauthorized code, potentially affecting the integrity of user data and operations. The main concern is confirming relevance and exposure.

  • Flaw allows code execution without user permission.
  • Impacts customer data and marketing workflows.
  • Confirm if this system is in use.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by reaching the Adobe Campaign Classic application over the network. Once access is gained, the attacker could leverage the incorrect authorization flaw to execute arbitrary code as the currently logged-in user. This could lead to a complete compromise of the affected system, allowing for data theft, further system intrusion, or disruption of services.

  • No authentication or special privileges needed.
  • Exploited via network access to the application.
  • Results in arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Adobe Campaign Classic could allow an unauthenticated attacker to execute arbitrary code on the system, potentially impacting system data and service behavior when the product is deployed in a network-accessible configuration.

  • System data and service behavior at risk.
  • Arbitrary code execution could occur remotely.
  • Attackers could gain control of the system.

Operational Fix

Recommended remediation, mitigation, and detection steps

The criticality of this Adobe Campaign Classic vulnerability impacting authorization and leading to potential code execution necessitates swift action. Application owners, in collaboration with infrastructure and security teams, must prioritize identifying all instances of Adobe Campaign Classic. Confirming reachability, business criticality, and accountable ownership is the immediate first step to accurately assess risk and plan a coordinated remediation strategy.

  • Application and infrastructure owners should lead the response.
  • Verify affected systems and their business criticality.
  • Plan remediation based on verified exposure and risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Adobe Campaign Classic?

Adobe Campaign Classic is an enterprise-grade marketing and customer relationship management platform. Organizations use it to automate multi-channel campaigns, manage complex customer databases, and orchestrate personalized messaging workflows across web and email channels.

What does Incorrect Authorization mean for CVE-2026-27302?

This vulnerability, classified as CWE-863, occurs when a system fails to properly verify if a user has permission to perform a specific action. In this case, the flaw allows an attacker to bypass these checks and execute arbitrary code, essentially tricking the software into running commands that should be restricted or blocked.

How can an attacker trigger this vulnerability?

An attacker triggers this flaw by reaching the application over a network connection. Because the system does not require authentication or user interaction to process the malicious request, the vulnerability can be initiated remotely. It is not triggered by standard, authorized administrative tasks performed by legitimate users.

Is my Adobe Campaign Classic instance at risk?

Your risk level depends heavily on network reachability. According to Halo Surface Signal, this software is commonly deployed as a public-facing service to support web-based marketing workflows. If your instance is accessible via the internet, it is at a higher risk of being reached by an external attacker compared to instances strictly isolated on an internal network.

What should I do first to manage this CVE?

Start by identifying all instances of Adobe Campaign Classic within your environment. Once you have a complete list, verify which systems are business-critical and determine their network visibility. Coordinating with your infrastructure team to document ownership and confirm the current deployment configuration is the necessary first step before applying remediation.

References