CVE-2026-48317

Adobe · Campaign Classic

Adobe Campaign Classic is vulnerable to Eval Injection, allowing a low-privileged attacker to execute arbitrary code.

Executive summary

An authenticated code injection vulnerability in Adobe Campaign Classic allows low-privileged users to achieve remote code execution.

Vulnerability

This vulnerability is an Eval Injection (CWE-95) flaw, where an attacker with low-level privileges can inject malicious directives into dynamically evaluated code to gain execution rights.

Business impact

A CVSS score of 9.6 highlights the significant risk posed by this vulnerability. While it requires low-level authentication, the ability to execute arbitrary code leads to a full system compromise, potential data theft, and the ability to manipulate application logic for malicious intent.

Remediation

Immediate Action: Apply the update to Adobe Campaign Classic version 7.4.3 build 9399 or higher as specified by the vendor.

Proactive Monitoring: Audit user activity logs to identify suspicious behavior from low-privileged accounts that may indicate an attempt to exploit the application.

Compensating Controls: Implement strict input validation and least-privilege access controls to limit the surface area available to authenticated users.

Exploitation status

Public Exploit Available: unknown

Analyst recommendation

Organizations should treat this as a critical update. Even though the exploit requires authenticated access, the risk of an insider threat or compromised user account successfully executing arbitrary code is significant and must be mitigated through patching.