Adobe Campaign Classic contains an unauthenticated code injection flaw rated CVSS 10.0 that allows arbitrary code execution with no user interaction required.
What Is It
CVE-2026-73369 is an Improper Control of Generation of Code ('Code Injection') vulnerability (CWE-94) in Adobe Campaign Classic (ACC). Per Adobe's advisory, the flaw "could result in arbitrary code execution in the context of the current user," and "exploitation of this issue does not require user interaction."
The CVSS 3.1 vector, AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, describes about the worst possible combination: reachable over the network, low attack complexity, no privileges, no user interaction, and full compromise of confidentiality, integrity, and availability. Scope is marked as changed, meaning impact extends beyond the vulnerable component's security boundary. That combination produces a base score of 10.0 CRITICAL, with an exploitability subscore of 3.9 (the maximum) and an impact subscore of 6.0.
Why It Matters
Pre-authentication remote code execution with a changed scope is the category of bug that turns a single exposed host into a pivot point. As scored, the vector lists no mitigating precondition, no credentials to phish, no user to trick into clicking, though real-world exploitation may still depend on deployment specifics such as network segmentation, reverse-proxy filtering, or non-default configuration. On that basis, any internet-reachable ACC instance running an affected build should be presumed exploitable by anyone who can reach it until proven otherwise.
The CVE was published 2026-09-22 and currently carries an NVD status of "Awaiting Analysis," so CPE enumeration and secondary scoring are not yet available. The CVSS data and affected-version ranges come directly from Adobe PSIRT as the primary source.
What's Vulnerable
- Product: Adobe Campaign Classic (ACC)
- Affected: all versions up to and including 7.4.4 build 9401
- Unaffected: 7.4.4 build 9402 and later
Adobe lists the default status for other versions as unaffected.
Patch Status
A fixed build exists. Upgrade Adobe Campaign Classic to 7.4.4 build 9402 or later, per Adobe Security Bulletin APSB26-142. Given the CVSS 10.0 rating and the absence of any authentication requirement, this should be treated as an emergency-change candidate rather than a routine patch cycle item.
CVE-2026-73369 does not appear in the CISA Known Exploited Vulnerabilities catalog as of 2026-09-22, so there is no federal remediation deadline or required action attached to it, and no public confirmation of active exploitation. Defenders should still monitor the KEV catalog for a subsequent addition.
Sources
- Adobe Security Bulletin APSB26-142; https://helpx.adobe.com/security/products/campaign/apsb26-142.html
- NVD, CVE-2026-73369, https://nvd.nist.gov/vuln/detail/CVE-2026-73369
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog