{"id":"CVE-2026-82013","published":"2026-09-22T18:17:21.657","lastModified":"2026-09-26T23:16:36.610","description":"Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed.","cvssScore":9.9,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-918"],"vendors":["adobe","linux","microsoft"],"products":["campaign","linux kernel","windows"],"references":[{"url":"https://helpx.adobe.com/security/products/campaign/apsb26-142.html","tags":["Vendor Advisory"]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The vulnerability allows a low-privileged attacker to exploit Server-Side Request Forgery (SSRF) to gain elevated access, potentially leading to privilege escalation.","exploitability":"Exploitation is relatively straightforward as it does not require user interaction, but preconditions include the attacker having low-level access to the system.","blast_radius":"If exploited, the impact could be severe, allowing the attacker to access internal resources and potentially escalate privileges across the network.","remediation":"Disable the affected feature or restrict access to the named endpoint as detailed in the vendor advisory.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["ssrf","privilege-escalation","web","internal-resources"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:47:16.509Z"}}