External risk intelligence

Adobe Campaign Classic Incorrect Authorization Vulnerability Allows Code Execution

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-71398

Adobe Campaign Classic is an enterprise marketing automation platform frequently deployed as a public-facing service to manage customer data, digital marketing campaigns, and web-accessible interactions, making its management or application interfaces commonly reachable from the internet.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in Adobe Campaign Classic, a platform used for marketing automation. The flaw could allow an attacker to execute arbitrary code without any user interaction, potentially impacting the confidentiality, integrity, and availability of systems. The primary concern is to confirm if this technology is relevant to our environment and if it is exposed.

  • Flaw allows unauthorized code execution.
  • Confirm if Adobe Campaign Classic is in use.
  • Assess potential impact and exposure.

Attack Path

How an attacker could exploit the issue

An attacker could reach an Adobe Campaign Classic component over the network without needing any special access or user interaction. If successful, this could allow them to execute arbitrary code with the same permissions as the current user.

  • No authentication or privileges required.
  • Network-accessible component.
  • Arbitrary code execution in user context.

Live Threat

Current exploitation, exposure, and threat context

Adobe Campaign Classic (ACC) is susceptible to an authorization flaw that, when exploited, could allow an attacker to execute arbitrary code on the system without user interaction. This could affect system data and service behavior by enabling unauthorized code execution within the context of the current user.

  • System data and service behavior at risk.
  • Arbitrary code execution is possible.
  • Unauthorized code execution may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

Determining ownership and initial actions for this Adobe Campaign Classic vulnerability requires coordination between application owners, infrastructure teams, and potentially vendor management. The first practical step is to identify all instances of Adobe Campaign Classic within your environment, assess their internet reachability and business criticality, and then pinpoint the accountable owner for each instance to prioritize remediation.

  • Application and infrastructure teams own remediation.
  • Verify internet exposure and business criticality.
  • Plan and execute risk-based remediation actions.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Adobe Campaign Classic?

Adobe Campaign Classic is an enterprise-grade marketing automation platform. Organizations use it to manage customer databases, orchestrate multi-channel digital marketing campaigns, and facilitate web-based customer interactions.

What does Incorrect Authorization mean for CVE-2026-71398?

This vulnerability, classified as CWE-863, means the software fails to properly verify if a user has permission to perform a specific action. Because of this flaw, the system may allow unauthorized users to execute arbitrary code, effectively bypassing security controls that should have blocked the request.

How does an attacker trigger this vulnerability?

An attacker can trigger this flaw by sending specially crafted requests over the network to the affected component. The attack does not require any prior authentication, special privileges, or interaction from a legitimate user to succeed.

Is my instance of Adobe Campaign Classic at risk?

According to Halo Surface Signal, this software is frequently deployed as a public-facing service to support web-accessible marketing interactions. If your instance is reachable from the internet, it is at a higher risk of being targeted than systems restricted to an internal network.

What should I do first to address this CVE?

Begin by creating a complete inventory of all Adobe Campaign Classic instances within your environment. Once identified, work with the relevant application and infrastructure teams to verify if these instances are internet-facing and determine the business criticality of each to prioritize your response.

References