External risk intelligence

Adobe Campaign Classic SSRF Vulnerability Allows Privilege Escalation

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-82013

Adobe Campaign Classic is an enterprise marketing automation platform designed to manage and deliver external customer-facing communications. It frequently operates as a web-accessible application to interact with external databases and API services, making its server-side components commonly reachable in internet-facing deployment environments.

Server-Side Request Forgery

Adobe Campaign

7.4.3 and earlier7.4.4

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability in Adobe Campaign Classic, a platform used for managing customer communications. The flaw, a Server-Side Request Forgery, could allow a low-privileged attacker to escalate their access and potentially control internal systems, as it enables unauthorized requests from the affected server.

  • Attackers could gain elevated access to internal systems.
  • This impacts a key customer communication platform.
  • Confirm relevance and exposure of Adobe Campaign Classic.

Attack Path

How an attacker could exploit the issue

An attacker with low privileges can exploit this vulnerability by making a request to an internal resource. This leads to the attacker gaining elevated access to internal resources, altering the scope of the attack.

  • Entry condition: Low-privileged access.
  • Trigger point: Server-side request forgery.
  • Resulting risk: Privilege escalation and internal resource access.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker with limited privileges to access sensitive internal resources within Adobe Campaign Classic. The attack does not require user interaction and can change the scope of the vulnerability's impact.

  • Internal resources could be accessed.
  • An attacker could send malicious requests.
  • Elevated access to internal systems.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given that Adobe Campaign Classic is a web-accessible enterprise marketing platform, the application owners and platform/infrastructure teams are likely responsible for addressing this vulnerability. The immediate first step is to identify all instances of affected Adobe Campaign Classic deployments, assess their business criticality and external reachability, and confirm the accountable owner for each instance before planning remediation.

  • Application owners should lead remediation efforts.
  • Verify external exposure and business criticality.
  • Plan remediation during the next maintenance window.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Adobe Campaign Classic?

Adobe Campaign Classic is an enterprise-grade marketing automation platform. Organizations use it to orchestrate complex customer communication workflows, manage multi-channel marketing campaigns, and interact with various external databases and API services to personalize customer experiences.

What does Server-Side Request Forgery mean for CVE-2026-82013?

This vulnerability, classified as CWE-918, occurs when an application can be tricked into making unintended requests to internal systems. In this case, the flaw allows an attacker to abuse the server's own network identity to query or interact with internal resources that would normally be off-limits to external users, ultimately leading to unauthorized privilege escalation.

How is this vulnerability triggered?

An attacker must possess low-privileged credentials to initiate the malicious request. Once authenticated at that basic level, the attacker sends a specially crafted command that forces the server to fetch data from an internal target. Notably, this process requires no interaction from other users to succeed.

Does my Adobe Campaign Classic instance need to be internet-facing?

Halo Surface Signal identifies that this product often functions as a web-accessible application to handle customer communications, which frequently places its server-side components in internet-facing environments. If your deployment is reachable from the public internet, the potential for an attacker to reach and exploit this vulnerability is significantly higher than if it were restricted to a private, internal-only network.

When should I prioritize a response to this threat?

First, conduct an inventory to locate all Adobe Campaign Classic deployments within your environment. Verify which instances are connected to the internet and determine their business criticality. Once mapped, identify the accountable application owners to coordinate a secure update during your next planned maintenance window.

References