CVE-2026-48323
Adobe · Campaign Classic
Adobe Campaign Classic contains a template engine vulnerability that allows unauthenticated remote attackers to execute arbitrary code.
Executive summary
A critical arbitrary code execution vulnerability in Adobe Campaign Classic, reachable without authentication, presents an extreme risk to infrastructure security.
Vulnerability
The application is susceptible to an Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336), allowing an unauthenticated attacker to achieve arbitrary code execution.
Business impact
With a CVSS score of 10.0, this vulnerability allows for complete system compromise. An attacker successfully exploiting this flaw could gain full control over the host environment, leading to data exfiltration, service disruption, and persistent backdoors within the organization.
Remediation
Immediate Action: Upgrade to Adobe Campaign Classic version 7.4.3 build 9399 or higher to resolve the template engine vulnerability.
Proactive Monitoring: Monitor server processes for unexpected child process execution or unusual network traffic originating from the application server.
Compensating Controls: Utilize a Web Application Firewall to inspect and sanitize incoming requests for suspicious template-related payloads.
Exploitation status
Public Exploit Available: unknown
Analyst recommendation
The maximum severity score of this vulnerability indicates that it is a high-priority threat that should be remediated immediately. Administrators should verify their current build versions and apply the vendor-provided patch without delay.