Adobe disclosed CVE-2026-71398, a CVSS 10.0 Incorrect Authorization vulnerability in Adobe Campaign Classic that, per the vendor, could result in arbitrary code execution over the network with no authentication and no user interaction.
What Is It
CVE-2026-71398 is an Incorrect Authorization weakness (CWE-863) in Adobe Campaign Classic (ACC). Per Adobe's PSIRT description, the flaw "could result in arbitrary code execution in the context of the current user," and exploitation "does not require user interaction." The CVE was published on 2026-08-11 and currently carries NVD status "Received," meaning NVD analysis is still pending.
Why It Matters
The vulnerability holds a CVSS 3.1 base score of 10.0 (CRITICAL): the maximum possible; with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H.
Every exploitability factor is worst-case: network attack vector, low attack complexity, no privileges required, and no user interaction, producing a full 3.9 exploitability subscore. Impact is high across confidentiality, integrity, and availability. Critically, scope is changed, meaning a successful exploit can affect resources beyond the vulnerable component's own security authority; this is what pushes the score to a perfect 10.0.
Adobe Campaign Classic is a marketing automation platform that typically holds large volumes of customer contact and campaign data, so code execution against it without authentication would offer a direct path to bulk data exposure and downstream lateral movement.
What's Vulnerable
- Product: Adobe Campaign Classic (ACC)
- Affected: All versions up to and including ACC v7: 7.4.3 build 9399
- Unaffected: ACC v7: 7.4.4 build 9400
No CPE entries have been assigned in the NVD record yet.
Patch Status
Adobe has shipped a fix. ACC v7 build 7.4.4 build 9400 is explicitly listed as unaffected; anything at or below 7.4.3 build 9399 should be upgraded to 7.4.4 build 9400 or later. Refer to Adobe Security Bulletin APSB26-123 for vendor upgrade guidance.
As of publication on 2026-08-11, CVE-2026-71398 is not listed in CISA's Known Exploited Vulnerabilities catalog, so there is no KEV-mandated remediation deadline and no public confirmation of exploitation in the wild. Given the 10.0 score and zero-prerequisite exploit path, treat patching as urgent regardless.
Sources
- Adobe Security Bulletin APSB26-123; https://helpx.adobe.com/security/products/campaign/apsb26-123.html
- NVD, CVE-2026-71398, https://nvd.nist.gov/vuln/detail/CVE-2026-71398
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog