Advisory · CVE-2026-75699
Adobe Campaign Classic code injection flaw enables unauthenticated RCE (CVE-2026-75699)
Adobe Campaign Classic is affected by an unauthenticated improper code-generation flaw that can lead to arbitrary code execution with scope changed. CVSS 10.0.
- Vendor
- Adobe
- Product
- Adobe Campaign Classic
- Identifier / CWE
- CVE-2026-75699
CWE-94 - Action timing
- Immediate
Explain it like I’m five
A form letter machine trusts whatever text you feed it. An attacker feeds it instructions instead of a letter, and the machine carries them out with its own authority.
- 01Target identified
An attacker reaches an internet-facing Adobe Campaign Classic instance with no credentials.
- 02Malicious input
They submit input that the application fails to control during code generation.
- 03Code executes
The injected code runs in the context of the current user with changed scope.
- 04Impact
Arbitrary code execution on the Campaign server, no user interaction required.
What happened
Adobe security bulletin APSB26-142 addresses multiple critical flaws in Adobe Campaign Classic. CVE-2026-75699 is an improper control of code generation (CWE-94) that an unauthenticated, remote attacker can exploit without user interaction, resulting in arbitrary code execution. Adobe Campaign Classic builds up to and including 7.4.4 build 9401; fixed in 7.4.4 build 9402. NVD rates it CVSS 10.0 (v3.1).
What to do
- Upgrade Adobe Campaign Classic to 7.4.4 build 9402 or later.
- Restrict network access to Campaign servers to trusted administrators while patching.
- Review application and system logs for unexpected process execution or web requests.
Management note
This is one of several unauthenticated RCE flaws fixed in the same Adobe bulletin. One patch cycle covers them all, so the risk is entirely in how long the upgrade waits.