CVE-2026-71398
Adobe has patched vulnerabilities in Adobe Campaign Classic. The vulnerabilities make it possible for an attacker to execute arbitrary code without user interaction. One of the vulnerabilities concerns improper authorization, allowing an attacker to perform actions outside the intended permissions. Another vulnerability concerns SQL injection, where the attack is partly dependent on factors outside the attacker's control. Through these vulnerabilities, an attacker can obtain elevated privileges and execute unauthorized code within the product.
CSIRTS triage
- What
- Multiple vulnerabilities including remote code execution, improper authorization, and SQL injection allow attackers to execute arbitrary code and obtain elevated privileges.
- Who is affected
- All deployments of Adobe Campaign Classic.
- Urgency
- High; remote code execution without user interaction is immediately exploitable.
- Action
- Apply the latest Adobe Campaign Classic security patches covering CVE-2026-27302, CVE-2026-48381, and CVE-2026-71398.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-71398
Get an email if CVE-2026-71398 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.64% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 48% of all EPSS-scored CVEs.
Advisory coverage (2)
- unknownNCSC-2026-0291 [1.00] [M/H] Vulnerabilities patched in Adobe Campaign Classicncsc-nl · 2026-08-12
- criticalCVE-2026-71398: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that coul…nvd · 2026-08-11
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-71398)