CVE-2026-82004
10.0Adobe · Adobe Campaign Classic
Adobe Campaign Classic is vulnerable to OS Command Injection, allowing unauthenticated remote attackers to execute arbitrary code with elevated system privileges.
Executive summary
A critical OS command injection vulnerability in Adobe Campaign Classic allows unauthenticated attackers to achieve remote code execution, posing a severe risk of full system compromise.
Vulnerability
The application fails to properly neutralize special elements in OS commands, enabling an unauthenticated attacker to inject and execute arbitrary commands. This vulnerability carries a CVSS score of 10.0, as it permits remote, unauthenticated access with full impact on confidentiality, integrity, and availability.
Business impact
The ability for an unauthenticated attacker to execute arbitrary code on the application server constitutes a catastrophic business risk. Successful exploitation could lead to total system takeover, unauthorized access to sensitive customer data, and potential lateral movement within the corporate network. Given the critical 10.0 CVSS severity, this vulnerability must be treated as an immediate priority for remediation.
Remediation
Immediate Action: Update all instances of Adobe Campaign Classic to build 9402 or later as specified in the vendor security advisory.
Proactive Monitoring: Inspect server and application logs for unusual command executions, unexpected child processes, or anomalous outbound network traffic originating from the Campaign Classic server.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block malicious command injection patterns, although this should only serve as a temporary measure until the patch is applied.
Exploitation status
Public Exploit Available: exploit_available (unknown)
Analyst recommendation
This vulnerability represents the highest level of security risk due to its potential for unauthenticated remote code execution. Administrators should prioritize the immediate deployment of the vendor-provided patch to build 9402. Failure to update the software promptly leaves the environment exposed to total compromise by remote adversaries.
More Adobe CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section