CVE-2026-48330
Adobe · Campaign Classic
Adobe Campaign Classic is vulnerable to SQL injection, which allows an unauthenticated remote attacker to execute arbitrary SQL commands and achieve arbitrary code execution.
Executive summary
A critical SQL injection vulnerability in Adobe Campaign Classic allows unauthenticated remote attackers to achieve full system compromise.
Vulnerability
This is an SQL injection vulnerability (CWE-89) where an unauthenticated attacker can supply malicious input to the application. The vulnerability allows for arbitrary command execution due to insufficient neutralization of special elements within SQL queries.
Business impact
The potential for arbitrary code execution poses a catastrophic risk to organizational data and infrastructure. A successful attack could lead to total database compromise, lateral movement within the network, and full loss of confidentiality, integrity, and availability. With a CVSS score of 10.0, this represents the highest level of severity and requires immediate remediation.
Remediation
Immediate Action: Update Adobe Campaign Classic to version 7.4.3 build 9399 or later immediately.
Proactive Monitoring: Monitor database query logs for unusual syntax, unexpected character strings, or unauthorized access attempts originating from external sources.
Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets designed to detect and block SQL injection patterns targeting Adobe Campaign infrastructure.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the critical CVSS score of 10.0 and the absence of required authentication, this vulnerability represents an urgent threat. Organizations must prioritize patching Adobe Campaign Classic to the specified fixed version to eliminate the risk of remote code execution.