Overview
Adobe has issued a Priority 1 security update for Adobe Campaign Classic, addressing three critical vulnerabilities that could allow unauthenticated remote attackers to execute arbitrary code. The flaws, tracked under APSB26‑134, affect on‑premises Campaign Classic v7.4.4 build 9400 and earlier on both Windows and Linux.
Vulnerability Details
- CVE‑2026‑76197 – OS command injection vulnerability.
- CVE‑2026‑76195 – OS command injection vulnerability.
- CVE‑2026‑76193 – Server‑Side Request Forgery (SSRF), tracked as CWE‑918.
These flaws allow attackers to:
- Inject malicious commands into the Campaign Classic process.
- Exploit SSRF to force servers to make unauthorized requests, potentially exposing internal services or chaining into RCE.
- Compromise confidentiality, integrity, and availability of campaign data and connected infrastructure.
Exploitation Risks
- Unauthenticated remote access: No credentials or user interaction required.
- Full compromise potential: Attackers could plant malware, steal credentials, or pivot into internal networks.
- Marketing data exposure: Unauthorized access to sensitive campaign information and customer records.
Defensive Guidance
Organizations should:
- Upgrade immediately: Patch to v7.4.4 build 9401.
- Restrict access: Limit Campaign Classic interfaces to trusted networks.
- Review logs: Investigate unusual process execution or outbound connections.
- Segment deployments: Reduce exposure of on‑premises components in hybrid environments.
Adobe confirmed that Adobe‑hosted instances are already remediated, requiring no customer action.
Expert in the Cloud Insight
This disclosure highlights how command injection and SSRF flaws remain high‑impact threats in enterprise platforms. With Priority 1 urgency, organizations must treat patching as non‑negotiable. The lesson is clear: marketing automation platforms are not just business tools — they are attack surfaces, and securing them is vital to protecting both brand trust and customer data.
Leave a Reply