CVE-2026-48448
Adobe · Adobe Campaign Classic
Adobe Campaign Classic is vulnerable to SQL injection, which may allow an unauthenticated attacker to disclose sensitive information from system memory.
Executive summary
A critical SQL injection vulnerability in Adobe Campaign Classic allows unauthenticated attackers to potentially access sensitive memory contents.
Vulnerability
The software fails to properly neutralize special elements used in SQL commands, resulting in an SQL injection vulnerability. This flaw is exploitable by an unauthenticated attacker over the network.
Business impact
The ability for an unauthenticated user to perform SQL injection poses a severe risk to data confidentiality. A successful exploit could lead to the unauthorized disclosure of sensitive information stored in memory, potentially exposing proprietary data or credentials, which justifies its high CVSS score of 8.6.
Remediation
Immediate Action: Update Adobe Campaign Classic to build 9398 or later, as provided in the vendor security advisory.
Proactive Monitoring: Review database access logs for unusual query patterns or unexpected input strings that deviate from standard application behavior.
Compensating Controls: Implement a Web Application Firewall (WAF) with strict SQL injection protection rules to block malicious payloads targeting the application interface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for unauthorized data disclosure and the ease of network-based exploitation, organizations should prioritize updating their Adobe Campaign Classic installations to the fixed version. Immediate application of the vendor-supplied patch is the most effective way to mitigate this risk.