CVE-2026-82003
8.5Adobe · Adobe Campaign Classic
Adobe Campaign Classic is vulnerable to improper input validation, allowing low-privileged authenticated attackers to achieve arbitrary code execution.
Executive summary
Adobe Campaign Classic contains an improper input validation flaw that allows low-privileged users to execute arbitrary code, posing a high risk to organizational infrastructure.
Vulnerability
The application suffers from improper input validation (CWE-20), which can be leveraged by a low-privileged authenticated user to execute arbitrary code within the context of the current user. Although exploitation requires specific conditions beyond the attacker's control, the vulnerability allows for a change in scope, potentially compromising the integrity and availability of the system.
Business impact
Successful exploitation of this vulnerability could lead to a total compromise of the affected Adobe Campaign Classic instance, including unauthorized data access and potential lateral movement within the network. With a CVSS score of 8.5, this high-severity flaw represents a significant threat to business operations, as it could result in the destruction or modification of sensitive marketing data and loss of control over critical enterprise communication workflows.
Remediation
Immediate Action: Update Adobe Campaign Classic to build 9402 or later as specified in the vendor security advisory.
Proactive Monitoring: Review system and application access logs for unusual command execution patterns or unauthorized attempts to access administrative functions by low-privileged accounts.
Compensating Controls: Deploy Web Application Firewall (WAF) rules designed to filter and sanitize input for the affected components, though these should only be treated as temporary measures until the patch is applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the potential for arbitrary code execution, this vulnerability demands immediate attention from security teams. Administrators should prioritize patching Adobe Campaign Classic to build 9402 to eliminate this attack surface, as relying on environmental factors to prevent exploitation is not a viable long-term security strategy.
More Adobe CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section