CVE-2026-27302
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
Description
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and Moreen·The Hacker News· Exploited Lazarus Group ransomware
- Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flawsen·The Hacker News· Patch ColdFusion web-app
- Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flawsen-us·SecurityWeek· Patch ColdFusion rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-27302 and every CVE in our database. Create a free account — no credit card required.
Create Free Account