External risk intelligence

Adobe Campaign Classic Incorrect Authorization Vulnerability Allows Code Execution.

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-75723

Adobe Campaign Classic is an enterprise marketing automation platform designed to manage and deliver public-facing web content, email campaigns, and external APIs. Due to its role as a central hub for external customer communications and web-based marketing interactions, it is commonly deployed with network-accessible endpoints.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

Adobe Campaign Classic has an important security flaw that could allow attackers to run unauthorized code on affected systems without any user interaction. This vulnerability, classified as critical, impacts how the system manages user access, potentially leading to broader system compromise. The primary concern is to confirm if our environment utilizes this specific Adobe product.

  • Unauthorized code execution flaw in Adobe Campaign.
  • Critical flaw with broad potential impact.
  • Confirm exposure and relevance to our systems.

Attack Path

How an attacker could exploit the issue

An attacker could reach this vulnerability by targeting the Adobe Campaign Classic system over the network. Since the vulnerability does not require user interaction and changes the scope, an unauthenticated attacker could exploit it to execute arbitrary code on the affected system, leading to a critical compromise.

  • No authentication required for attack.
  • Vulnerability triggered remotely.
  • Risk of arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Adobe Campaign Classic could allow an unauthenticated attacker to execute arbitrary code on the system. When supported by the advisory, this could affect system data and service behavior through network access.

  • System data and service behavior are at risk.
  • Arbitrary code execution via network access.
  • Potential for widespread system compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts Adobe Campaign Classic, a marketing automation platform used for managing external communications. Responsibility for addressing this issue likely falls to the application owners, potentially in coordination with infrastructure and security teams, depending on the deployment and whether the affected instances are network-accessible. The immediate priority is to identify all deployed instances, assess their exposure and business criticality, confirm the accountable owner, and then develop a remediation plan based on this risk assessment.

  • Application and infrastructure teams own remediation.
  • Verify external accessibility and business impact.
  • Plan and execute risk-based remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Adobe Campaign Classic?

Adobe Campaign Classic is an enterprise-grade marketing automation platform. Organizations use it to centralize customer data, manage email and SMS communications, and orchestrate complex cross-channel marketing campaigns. Because it often integrates with web-based interfaces and external customer APIs, it acts as a critical hub for delivering public-facing content.

What does an Incorrect Authorization vulnerability mean for CVE-2026-75723?

This vulnerability, classified as CWE-863, occurs when the software fails to properly verify that a user has permission to perform a specific action. In the context of CVE-2026-75723, this security weakness allows an attacker to bypass authorization checks, enabling them to execute arbitrary code on the underlying system as if they were a legitimate, authorized user.

How is this vulnerability triggered by an attacker?

An attacker triggers this flaw by sending specifically crafted network requests to the Adobe Campaign Classic system. Because the vulnerability does not require any user interaction—meaning no one needs to click a link or log in for the attack to succeed—the system processes these unauthorized commands automatically upon receipt. Internal system actions that do not involve external network input are not the primary target for this trigger path.

Why should I care about my system's network accessibility?

According to Halo Surface Signal, Adobe Campaign Classic is frequently deployed with network-accessible endpoints because it manages external-facing customer communications. If your instance is reachable over the internet, it is at higher risk because attackers can attempt to trigger the vulnerability remotely without needing prior access to your internal network.

What should I do if I run this software?

First, conduct a discovery exercise to identify all instances of Adobe Campaign Classic within your environment. Once identified, evaluate whether those instances are accessible from the network. Coordinate with your application owners to prioritize these systems for remediation, ensuring you have a clear plan to apply the necessary security updates provided by the vendor.

References