CVE-2026-89276

9.9

Adobe · Adobe Campaign Classic

Adobe Campaign Classic is vulnerable to code injection, allowing a low-privileged attacker to execute arbitrary code without user interaction.

Executive summary

Adobe Campaign Classic is affected by a critical code injection vulnerability that allows low-privileged attackers to achieve remote code execution.

Vulnerability

The application is susceptible to CWE-94, which is an improper control of generation of code. A low-privileged, authenticated attacker can exploit this flaw to execute arbitrary code on the underlying system without requiring user interaction.

Business impact

This vulnerability carries a CVSS score of 9.9, reflecting its critical severity and the potential for full system compromise. Successful exploitation allows an attacker to gain unauthorized code execution, which could lead to complete data exfiltration, loss of system integrity, and significant operational disruption. Given the nature of the software, this could also facilitate lateral movement within the corporate network.

Remediation

Immediate Action: Update Adobe Campaign Classic to build 9402 or later as specified in the vendor security advisory.

Proactive Monitoring: Review system and application access logs for unusual command execution patterns or unauthorized modifications to application code.

Compensating Controls: Deploy Web Application Firewall rules to detect and block suspicious payloads targeting the application input fields associated with code generation or processing.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Due to the critical severity of this vulnerability and its potential for arbitrary code execution, organizations must prioritize patching Adobe Campaign Classic to version 7.4.4 build 9402 or higher. Administrators should verify their current build versions immediately and implement the vendor recommended updates to eliminate this high-risk attack vector.

More Adobe CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources