CVE-2026-82008
9.9Adobe · Adobe Campaign Classic
Adobe Campaign Classic is vulnerable to improper input validation, allowing a low-privileged, authenticated attacker to achieve remote arbitrary code execution without user interaction.
Executive summary
Adobe Campaign Classic contains a critical input validation vulnerability that allows authenticated attackers to execute arbitrary code, posing a severe risk to system integrity and confidentiality.
Vulnerability
This vulnerability is caused by improper input validation (CWE-20) within Adobe Campaign Classic, which can be exploited by an authenticated user with low privileges to perform remote code execution. The attack vector is network-based and does not require user interaction, with the exploit resulting in a changed security scope.
Business impact
The ability for an attacker to execute arbitrary code with the privileges of the application provides a direct path to full system compromise. Given the CVSS score of 9.9, this vulnerability carries a critical severity rating, as it enables unauthorized data access, potential lateral movement within the network, and the disruption of business-critical marketing operations.
Remediation
Immediate Action: Update Adobe Campaign Classic to version 7.4.4 build 9402 or later as specified in the vendor security advisory.
Proactive Monitoring: Review application access logs for unusual patterns or unexpected command execution attempts originating from low-privileged user accounts.
Compensating Controls: Implement strict network segmentation and utilize a Web Application Firewall to monitor and filter suspicious traffic directed at the Adobe Campaign Classic interface.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Due to the critical severity and the potential for total system compromise, administrators must prioritize patching Adobe Campaign Classic immediately. Organizations should verify their current build version and apply the recommended update to ensure the vulnerability is fully remediated.
More Adobe CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section