CVE-2026-48331
published 2026-08-03CVE-2026-48331: Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this…
PriorityP261critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
0.48%
39.4th percentile
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_campaign_classic | <= ACC v7: 7.4.3 build 9398 | — |
| adobe | campaign | <= 7.4.2 | — |
| adobe | campaign | — | — |
| adobe | campaign | — | — |
| adobe | campaign | — | — |
| adobe | campaign | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Adobe Campaign Classic server-side request forgery
vuldb·2026-08-04·CVSS 10.0
CVE-2026-48331 [CRITICAL] Adobe Campaign Classic server-side request forgery
A vulnerability classified as critical was found in Adobe Campaign Classic. Affected is an unknown function. Executing a manipulation can lead to server-side request forgery.
The identification of this vulnerability is CVE-2026-48331. The attack may be launched remotely. There is no exploit available.
GHSA
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation.
ghsa_unreviewed·2026-08-04
CVE-2026-48331 [CRITICAL] CWE-918 Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation.
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-03
Published