PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-48331 Adobe CVE debrief

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. This issue does not require user interaction and has a CVSS score of 10 with Critical severity. The vulnerability's scope is changed. Organizations should review and address this vulnerability promptly to prevent potential attacks. The CVE record was published on 2026-08-03T23:16:46.443Z and has not been modified since then. The NVD entry is currently Analyzed.

Vendor
Adobe
Product
Adobe Campaign Classic
CVSS
CRITICAL 10
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-03
Original CVE updated
2026-08-28
Advisory published
2026-08-03
Advisory updated
2026-08-28

Who should care

Organizations using Adobe Campaign Classic, security teams responsible for patch management, administrators of affected systems, and IT teams overseeing network security should prioritize addressing this vulnerability. Reviewing and restricting network access to Adobe Campaign Classic instances can help mitigate potential risks. Monitoring for suspicious activity or anomalies in Adobe Campaign Classic logs is also recommended to detect any exploitation attempts. Additionally, organizations should ensure that their patch management processes are updated to include Adobe Campaign Classic, and that relevant teams are informed about the potential risks associated with this vulnerability. This includes reviewing compensating controls for exposed systems while remediation is scheduled and verified, and checking relevant monitoring, detection, and logs for exposed assets that need extra review. A thorough review of the affected product deployments in managed environments is necessary to assign an owner for follow-up and plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. The CVE record indicates Adobe Campaign Classic is affected by a Server-Side Request Forgery (SSRF) vulnerability, which could result in privilege escalation. Exploitation does not require user interaction. The scope is changed. CVSS score is 10 with a Critical severity. The NVD entry provides additional details about the vulnerability, and organizations should review this information to understand the potential impact on their systems. Furthermore, organizations should confirm whether affected product deployments exist in their environments and assign an owner for follow-up. They should also review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Planning vendor-supported updates or mitigations through normal change control where exposure is confirmed is crucial, as is reviewing compensating controls for exposed systems while remediation is scheduled and verified. Checking relevant monitoring, detection, and logs for exposed assets that need extra review is also essential. This vulnerability may

Technical summary

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. This issue does not require user interaction and has a CVSS score of 10 with Critical severity. The vulnerability's scope is changed.

Defensive priority

Organizations using Adobe Campaign Classic should prioritize patching to prevent potential privilege escalation attacks.

Recommended defensive actions

  • Apply patches or updates provided by Adobe to address the SSRF vulnerability
  • Review and restrict network access to Adobe Campaign Classic instances
  • Monitor for suspicious activity or anomalies in Adobe Campaign Classic logs

Evidence notes

The CVE record indicates Adobe Campaign Classic is affected by a Server-Side Request Forgery (SSRF) vulnerability, which could result in privilege escalation. Exploitation does not require user interaction. The scope is changed. CVSS score is 10 with a Critical severity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-48331 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-48331

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-48331 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48331

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.