Adobe has disclosed a critical (CVSS 9.1) incorrect authorization vulnerability in Adobe Campaign Classic that, per Adobe's advisory, could allow an unauthenticated, remote attacker to execute arbitrary code without any user interaction.
What Is It
CVE-2026-75728 is an Incorrect Authorization flaw (CWE-863) in Adobe Campaign Classic (ACC). According to Adobe's PSIRT advisory, the weakness "could result in arbitrary code execution in the context of the current user." Adobe's advisory indicates that exploitation would not require user interaction, and the scored vector assumes no prior authentication. Adobe has not published exploitation details or a proof of concept, so the practical reliability of an attack against a given deployment is not publicly established.
The CVSS 3.1 vector, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, describes the worst practical combination for an internet-reachable application: network attack vector, low attack complexity, no privileges required, and no user interaction, yielding a maximum exploitability subscore of 3.9. Impact is high to both confidentiality and integrity, with no availability impact. The resulting base score is 9.1, rated CRITICAL.
The record was published 2026-09-22 and is still marked "Awaiting Analysis" in NVD, so enrichment such as CPE mappings has not yet been completed.
Why It Matters
An authorization bypass that reaches code execution with zero authentication and zero user interaction would collapse the exploitation chain to a single step. Adobe Campaign Classic is a marketing orchestration platform that typically holds large volumes of customer contact and campaign data and integrates with surrounding delivery infrastructure, which raises the value of a successful compromise beyond the host itself.
Neither Adobe's advisory nor the NVD record cited here reports active exploitation, and this brief makes no determination about the vulnerability's status in CISA's Known Exploited Vulnerabilities catalog; defenders tracking KEV-driven deadlines should check the catalog directly for the current entry status. Regardless of that status, the scored attack profile argues for treating this on a short internal remediation timeline.
What's Vulnerable
Per Adobe's affected-product data:
- Affected: Adobe Campaign Classic, all versions up to and including 7.4.4 build 9401
- Not affected: Adobe Campaign Classic 7.4.4 build 9402 and later
Adobe lists a default status of "unaffected," meaning only the enumerated range above is in scope.
Patch Status
A fix is available. Upgrading Adobe Campaign Classic to 7.4.4 build 9402 or later remediates the issue. No workarounds or mitigations are described in the supplied source material. Because ACC build numbers are the deciding factor here, verify the exact build rather than the marketing version when confirming remediation.
Sources
- Adobe Security Bulletin APSB26-142 (Adobe Campaign), https://helpx.adobe.com/security/products/campaign/apsb26-142.html
- NVD, CVE-2026-75728, https://nvd.nist.gov/vuln/detail/CVE-2026-75728
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog