CVE-2026-48317
Adobe · Campaign Classic
Adobe Campaign Classic is vulnerable to Eval Injection, allowing a low-privileged attacker to execute arbitrary code.
Executive summary
An authenticated code injection vulnerability in Adobe Campaign Classic allows low-privileged users to achieve remote code execution.
Vulnerability
This vulnerability is an Eval Injection (CWE-95) flaw, where an attacker with low-level privileges can inject malicious directives into dynamically evaluated code to gain execution rights.
Business impact
A CVSS score of 9.6 highlights the significant risk posed by this vulnerability. While it requires low-level authentication, the ability to execute arbitrary code leads to a full system compromise, potential data theft, and the ability to manipulate application logic for malicious intent.
Remediation
Immediate Action: Apply the update to Adobe Campaign Classic version 7.4.3 build 9399 or higher as specified by the vendor.
Proactive Monitoring: Audit user activity logs to identify suspicious behavior from low-privileged accounts that may indicate an attempt to exploit the application.
Compensating Controls: Implement strict input validation and least-privilege access controls to limit the surface area available to authenticated users.
Exploitation status
Public Exploit Available: unknown
Analyst recommendation
Organizations should treat this as a critical update. Even though the exploit requires authenticated access, the risk of an insider threat or compromised user account successfully executing arbitrary code is significant and must be mitigated through patching.