CVE-2026-82010
9.9Adobe · Campaign Classic
Adobe Campaign Classic is vulnerable to SQL injection, which may allow a low-privileged attacker to achieve remote code execution without user interaction.
Executive summary
A critical SQL injection vulnerability in Adobe Campaign Classic allows low-privileged attackers to execute arbitrary code with elevated impact, posing a severe risk to system integrity.
Vulnerability
This vulnerability consists of an improper neutralization of special elements used in an SQL command, classified as CWE-89. An attacker with low-level privileges can trigger this flaw to achieve remote code execution, as the vulnerability impacts the system scope and permits command execution in the context of the user.
Business impact
The potential for remote code execution via SQL injection presents an extreme risk to the confidentiality, integrity, and availability of the affected environment. Given the CVSS score of 9.9, this vulnerability is classified as critical, as it allows attackers to bypass standard access controls and potentially gain full control over the underlying database and host system. Failure to remediate this issue could lead to complete data compromise and significant operational disruption.
Remediation
Immediate Action: Update Adobe Campaign Classic to build 9402 or later to apply the vendor-supplied fix.
Proactive Monitoring: Review database and application access logs for unusual query patterns or unexpected administrative commands being executed by standard user accounts.
Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets designed to detect and block common SQL injection payloads targeting the application interface.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability represents a critical security risk due to the potential for arbitrary code execution. Organizations should prioritize updating all instances of Adobe Campaign Classic to build 9402 or higher immediately. Given the high severity and the nature of the flaw, administrators must ensure that the patch is applied across all production environments to eliminate the risk of exploitation.
More Adobe CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section