CVE-2026-48326
Adobe · Campaign Classic
Adobe Campaign Classic is vulnerable to SQL injection, which allows a low-privileged authenticated attacker to execute arbitrary code.
Executive summary
An authenticated SQL injection vulnerability in Adobe Campaign Classic permits low-privileged attackers to execute arbitrary code, threatening system integrity.
Vulnerability
This is an SQL injection vulnerability (CWE-89) that requires the attacker to be authenticated with low privileges. By injecting malicious SQL, the attacker can execute arbitrary code within the context of the current user.
Business impact
While this vulnerability requires low-level authentication, the impact remains severe as it allows an attacker to elevate their capabilities and execute code on the host system. This could lead to data exfiltration or the installation of persistent backdoors. The CVSS score of 9.9 underscores the critical risk posed to the confidentiality and integrity of the application.
Remediation
Immediate Action: Update Adobe Campaign Classic to version 7.4.3 build 9399 or later.
Proactive Monitoring: Audit user activity logs for suspicious query patterns or unauthorized attempts to access system-level functions by low-privileged accounts.
Compensating Controls: Enforce strict principle of least privilege for application accounts and utilize WAF rules to sanitize inputs for authenticated sessions.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations should prioritize patching this vulnerability to prevent authenticated users from escalating their access to full system control. Promptly updating to the latest build is the most effective way to remediate this critical security flaw.