PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-48331 Adobe CVE debrief

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. This issue does not require user interaction and has a CVSS score of 10 with Critical severity. The vulnerability's scope is changed. Organizations should review and address this vulnerability promptly to prevent potential attacks. The CVE record was published on 2026-08-03T23:16:46.443Z and has not been modified since then. The NVD entry is currently Analyzed.

Vendor
Adobe
Product
Adobe Campaign Classic
CVSS
CRITICAL 10
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-03
Original CVE updated
2026-08-06
Advisory published
2026-08-03
Advisory updated
2026-08-06

Who should care

Organizations using Adobe Campaign Classic, security teams responsible for patch management, administrators of affected systems, and IT teams overseeing network security should prioritize addressing this vulnerability. Reviewing and restricting network access to Adobe Campaign Classic instances can help mitigate potential risks. Monitoring for suspicious activity or anomalies in Adobe Campaign Classic logs is also recommended to detect any exploitation attempts. Additionally, organizations should ensure that their patch management processes are updated to include Adobe Campaign Classic, and that relevant teams are informed about the potential risks associated with this vulnerability. This includes reviewing compensating controls for exposed systems while remediation is scheduled and verified, and checking relevant monitoring, detection, and logs for exposed assets that need extra review. A thorough review of the affected product deployments in managed environments is necessary to assign an owner for follow-up and plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. The CVE record indicates Adobe Campaign Classic is affected by a Server-Side Request Forgery (SSRF) vulnerability, which could result in privilege escalation. Exploitation does not require user interaction. The scope is changed. CVSS score is 10 with a Critical severity. The NVD entry provides additional details about the vulnerability, and organizations should review this information to understand the potential impact on their systems. Furthermore, organizations should confirm whether affected product deployments exist in their environments and assign an owner for follow-up. They should also review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Planning vendor-supported updates or mitigations through normal change control where exposure is confirmed is crucial, as is reviewing compensating controls for exposed systems while remediation is scheduled and verified. Checking relevant monitoring, detection, and logs for exposed assets that need extra review is also essential. This vulnerability may

Technical summary

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. This issue does not require user interaction and has a CVSS score of 10 with Critical severity. The vulnerability's scope is changed.

Defensive priority

Organizations using Adobe Campaign Classic should prioritize patching to prevent potential privilege escalation attacks.

Recommended defensive actions

  • Apply patches or updates provided by Adobe to address the SSRF vulnerability
  • Review and restrict network access to Adobe Campaign Classic instances
  • Monitor for suspicious activity or anomalies in Adobe Campaign Classic logs

Evidence notes

The CVE record indicates Adobe Campaign Classic is affected by a Server-Side Request Forgery (SSRF) vulnerability, which could result in privilege escalation. Exploitation does not require user interaction. The scope is changed. CVSS score is 10 with a Critical severity.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-03T23:16:46.443Z and has not been modified since then.