CVE-2026-89275
10.0Adobe · Campaign Classic
Adobe Campaign Classic is vulnerable to improper code injection, allowing unauthenticated remote attackers to execute arbitrary code with elevated privileges.
Executive summary
A critical code injection vulnerability in Adobe Campaign Classic allows for unauthenticated remote code execution, posing an extreme risk to infrastructure integrity.
Vulnerability
The application suffers from CWE-94, an improper control of generation of code vulnerability. An unauthenticated attacker can trigger arbitrary code execution without user interaction, resulting in a full compromise of the affected system.
Business impact
The CVSS score of 10.0 reflects the maximum severity of this flaw, as it allows complete system takeover by remote, unauthenticated actors. Successful exploitation would lead to full data exfiltration, permanent loss of system control, and potential lateral movement into the internal network, representing a catastrophic risk to business continuity.
Remediation
Immediate Action: Update Adobe Campaign Classic to build 9402 or later as specified in the vendor security advisory.
Proactive Monitoring: Inspect server logs for unusual process execution, unexpected outbound network connections, or unauthorized attempts to access sensitive configuration files.
Compensating Controls: Deploy strict egress filtering and WAF rules to block suspicious payloads targeting the Adobe Campaign application interface until patching is finalized.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical CVSS severity and the nature of remote code execution, this vulnerability demands immediate attention from security teams. Organizations must prioritize the update to build 9402 or higher across all production environments to close the attack vector. Failure to remediate could result in a total compromise of the application and underlying host systems.
More Adobe CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section