External risk intelligence

Adobe Campaign Classic SSRF Vulnerability Allows Privilege Escalation.

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-83660

Adobe Campaign Classic is an enterprise marketing automation platform frequently deployed as an internet-facing application to manage customer-facing campaigns, web forms, and external marketing services, making its web interface and API endpoints commonly accessible from the internet.

Server-Side Request Forgery

Adobe Campaign

7.4.3 and earlier7.4.4

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Adobe Campaign Classic, allowing unauthorized access to internal systems and potential data compromise without any user interaction. This issue, classified as Server-Side Request Forgery, could allow an attacker to manipulate the application into making unintended requests on behalf of the server, potentially leading to privilege escalation and significant disruption.

  • Unauthorized access to internal systems.
  • Affects customer engagement and marketing platforms.
  • Confirm relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can leverage a Server-Side Request Forgery vulnerability in Adobe Campaign Classic to trigger requests to internal systems. This could allow them to escalate their privileges within the affected environment.

  • No authentication or user interaction needed.
  • Triggered via crafted network requests.
  • Risk of privilege escalation.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Adobe Campaign Classic could allow an attacker to manipulate the application into making unintended network requests. This could lead to unauthorized access to internal network resources or sensitive data when the application is configured to interact with external services.

  • Internal network resources are at risk.
  • Server requests can be forged.
  • Unauthorized access to internal systems.

Operational Fix

Recommended remediation, mitigation, and detection steps

This Server-Side Request Forgery vulnerability in Adobe Campaign Classic likely impacts teams responsible for marketing automation platforms, application ownership, and potentially infrastructure or security teams depending on deployment. The first practical step is to confirm where Adobe Campaign Classic is deployed, assess its exposure and criticality, identify the accountable owner, and then prioritize remediation efforts.

  • Application owners must manage the issue.
  • Verify external accessibility and business impact.
  • Plan risk-based remediation with the vendor.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Adobe Campaign Classic?

Adobe Campaign Classic is an enterprise marketing automation platform. Organizations use it to coordinate multi-channel customer engagement, manage web forms, and integrate with various external marketing services.

What does Server-Side Request Forgery mean for CVE-2026-83660?

This vulnerability is classified as CWE-918. It means an attacker can force the Adobe Campaign Classic server to send unauthorized network requests to destinations it shouldn't access, effectively tricking the server into acting on the attacker's behalf.

How is this vulnerability triggered?

An attacker triggers this by sending crafted network requests to the application. Because the system is vulnerable to this specific forgery flaw, no authentication or interaction from a user is required to initiate the unintended requests.

How relevant is this to my organization?

According to Halo Surface Signal, Adobe Campaign Classic is often deployed as an internet-facing application to support external marketing services. If your instance is accessible from the internet, it is at higher risk of being targeted by external actors to reach internal systems.

What should I do if I run Adobe Campaign Classic?

First, locate where the software is deployed in your environment to understand its specific accessibility. Identify the team responsible for the platform, assess the potential impact to your internal network, and coordinate with the vendor to plan and apply the necessary updates.

References