Adobe has disclosed CVE-2026-27302, a CVSS 10.0 incorrect authorization vulnerability in Adobe Campaign Classic that, per the vendor advisory, could result in arbitrary code execution. The scored vector indicates the flaw is reachable over the network without prior authentication or user interaction.
What Is It
CVE-2026-27302 is an Incorrect Authorization vulnerability (CWE-863) in Adobe Campaign Classic (ACC). Per Adobe's advisory, the flaw "could result in arbitrary code execution in the context of the current user," and exploitation "does not require user interaction."
The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, producing a base score of 10.0 (CRITICAL): the maximum possible. Every exploitability factor is at its worst case: network-reachable, low attack complexity, no privileges required, no user interaction. Confidentiality, integrity, and availability impacts are all rated High, and the scope is Changed, meaning successful exploitation affects resources beyond the vulnerable component's own security authority.
Note that the "no privileges required" rating is what establishes the unauthenticated characterization here; Adobe's prose describes impact "in the context of the current user" without further detailing the attack path. Adobe has not published exploitation prerequisites beyond the vector, so the precise conditions under which the authorization check fails are not publicly documented.
The record was published by Adobe PSIRT ([email protected]) on 2026-08-11 and currently carries NVD status "Received," so NVD-assigned CPE data and secondary analysis are not yet available.
Why It Matters
A score of 10.0 is rare and reflects the combination of pre-authentication network reach and a changed scope. There is no mitigating condition in the vector; no credential requirement, no victim interaction, no complex preconditions. Campaign Classic instances that are reachable from untrusted networks should be treated as directly exposed.
CVE-2026-27302 is not listed in CISA's Known Exploited Vulnerabilities catalog as of publication. There is therefore no public confirmation of active exploitation and no KEV-mandated remediation deadline for federal civilian agencies at this time. That status can change; the catalog is the authoritative place to re-check.
What's Vulnerable
Per Adobe's affected-product data:
- Adobe Campaign Classic (ACC) v7: all versions up to and including 7.4.3 build 9399: affected
- Adobe Campaign Classic (ACC) v7: 7.4.4 build 9400: unaffected
The vendor lists a default status of "affected," so builds not explicitly enumerated should be assumed vulnerable until confirmed otherwise against the advisory.
Patch Status
A fix is available. ACC v7 build 7.4.4 build 9400 is listed as unaffected and is the remediation target for the affected v7 line. Operators running 7.4.3 build 9399 or earlier should upgrade to 7.4.4 build 9400 per Adobe Security Bulletin APSB26-123.
No workarounds or mitigations beyond upgrading are described in the supplied source material.
Sources
- Adobe Security Bulletin APSB26-123, Adobe Campaign Classic, https://helpx.adobe.com/security/products/campaign/apsb26-123.html
- NVD, CVE-2026-27302, https://nvd.nist.gov/vuln/detail/CVE-2026-27302
- CISA, Known Exploited Vulnerabilities Catalog, https://www.cisa.gov/known-exploited-vulnerabilities-catalog