PT-2026-48274 · Adobe · Campaign Classic

CVE-2026-47938

·

Published

2026-06-09

·

Updated

2026-08-26

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe Campaign Classic (ACC) versions prior to 7.4.3 build 9395
Description A Server-Side Request Forgery (SSRF) issue exists where the server can be coerced into making unauthorized requests. This can lead to privilege escalation or arbitrary code execution within the context of the current user. Exploitation does not require user interaction.
Recommendations Update to a version later than 7.4.3 build 9394.

Fix

LPE

Incorrect Authorization

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08392
CVE-2026-47938

Affected Products

Campaign Classic