CVE-2026-48323

Adobe · Campaign Classic

Adobe Campaign Classic contains a template engine vulnerability that allows unauthenticated remote attackers to execute arbitrary code.

Executive summary

A critical arbitrary code execution vulnerability in Adobe Campaign Classic, reachable without authentication, presents an extreme risk to infrastructure security.

Vulnerability

The application is susceptible to an Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336), allowing an unauthenticated attacker to achieve arbitrary code execution.

Business impact

With a CVSS score of 10.0, this vulnerability allows for complete system compromise. An attacker successfully exploiting this flaw could gain full control over the host environment, leading to data exfiltration, service disruption, and persistent backdoors within the organization.

Remediation

Immediate Action: Upgrade to Adobe Campaign Classic version 7.4.3 build 9399 or higher to resolve the template engine vulnerability.

Proactive Monitoring: Monitor server processes for unexpected child process execution or unusual network traffic originating from the application server.

Compensating Controls: Utilize a Web Application Firewall to inspect and sanitize incoming requests for suspicious template-related payloads.

Exploitation status

Public Exploit Available: unknown

Analyst recommendation

The maximum severity score of this vulnerability indicates that it is a high-priority threat that should be remediated immediately. Administrators should verify their current build versions and apply the vendor-provided patch without delay.