CVE-2026-48330

Adobe · Campaign Classic

Adobe Campaign Classic is vulnerable to SQL injection, which allows an unauthenticated remote attacker to execute arbitrary SQL commands and achieve arbitrary code execution.

Executive summary

A critical SQL injection vulnerability in Adobe Campaign Classic allows unauthenticated remote attackers to achieve full system compromise.

Vulnerability

This is an SQL injection vulnerability (CWE-89) where an unauthenticated attacker can supply malicious input to the application. The vulnerability allows for arbitrary command execution due to insufficient neutralization of special elements within SQL queries.

Business impact

The potential for arbitrary code execution poses a catastrophic risk to organizational data and infrastructure. A successful attack could lead to total database compromise, lateral movement within the network, and full loss of confidentiality, integrity, and availability. With a CVSS score of 10.0, this represents the highest level of severity and requires immediate remediation.

Remediation

Immediate Action: Update Adobe Campaign Classic to version 7.4.3 build 9399 or later immediately.

Proactive Monitoring: Monitor database query logs for unusual syntax, unexpected character strings, or unauthorized access attempts originating from external sources.

Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets designed to detect and block SQL injection patterns targeting Adobe Campaign infrastructure.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical CVSS score of 10.0 and the absence of required authentication, this vulnerability represents an urgent threat. Organizations must prioritize patching Adobe Campaign Classic to the specified fixed version to eliminate the risk of remote code execution.