{"id":"CVE-2026-75699","published":"2026-09-22T18:17:15.760","lastModified":"2026-09-26T23:16:35.460","description":"Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.","cvssScore":10,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-94"],"vendors":["adobe","linux","microsoft"],"products":["campaign","linux kernel","windows"],"references":[{"url":"https://helpx.adobe.com/security/products/campaign/apsb26-142.html","tags":["Vendor Advisory"]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The vulnerability allows an attacker to inject arbitrary code, potentially leading to full system compromise without user interaction.","exploitability":"Exploitation is straightforward as no user interaction is required, but specific conditions must be met for the attack to succeed.","blast_radius":"If exploited, the attacker could gain full control over the affected system, impacting all users and services running on it.","remediation":"Upgrade to the fixed version 12.1.0.0 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","code-injection","patch-required"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:40:55.175Z"}}