CVE-2026-73369: Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94)
Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
Does exploitation require authentication or user interaction?
No. The vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction.
What level of access could an attacker gain?
Successful exploitation could allow arbitrary code execution in the context of the current user. The reported impact includes high confidentiality, integrity, and availability impact, with scope changed.
Which deployments are affected?
The provided information identifies Adobe Campaign Classic as affected, but does not specify affected versions, configurations, or whether any deployment is safe by default.