External risk intelligence

Adobe Campaign Classic Eval Injection Vulnerability Allows Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-48317

Adobe Campaign Classic is an enterprise marketing automation platform designed to manage and deliver public-facing campaigns, web forms, and email services. These systems are commonly deployed as internet-facing applications to interact with external audiences, making them regularly reachable from the public internet in standard deployment patterns.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

An Improper Neutralization of Directives in Dynamically Evaluated Code vulnerability has been identified in Adobe Campaign Classic, potentially allowing unauthorized code execution. This issue could enable a low-privileged attacker to run arbitrary code remotely, altering the system's scope and impacting data confidentiality and integrity.

  • Code execution flaw in Adobe Campaign Classic.
  • Impacts data confidentiality and integrity.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker with low privileges can reach an administrative function within Adobe Campaign Classic that does not properly validate user input. This can allow them to execute arbitrary code on the affected system, potentially leading to a full compromise. The vulnerability can be triggered remotely without requiring any user interaction.

  • Low-privileged access is required.
  • Vulnerable function can be reached remotely.
  • Arbitrary code execution is possible.

Live Threat

Current exploitation, exposure, and threat context

The vulnerability in Adobe Campaign Classic could allow a low-privileged attacker to execute arbitrary code within the context of the current user, without requiring user interaction. This could potentially affect system data and service behavior when exploited.

  • System data and service behavior.
  • Via network access by an attacker.
  • Arbitrary code execution on the system.

Operational Fix

Recommended remediation, mitigation, and detection steps

This Improper Neutralization of Directives in Dynamically Evaluated Code vulnerability in Adobe Campaign Classic (ACC) necessitates action from teams managing marketing technology and the underlying infrastructure. The first practical step is to identify all ACC instances, confirm their exposure and criticality, and then engage the accountable application or platform owners to plan remediation based on risk.

  • Marketing technology and platform teams own this.
  • Verify ACC instances and exposure.
  • Plan risk-based remediation activities.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Adobe Campaign Classic?

Adobe Campaign Classic is an enterprise marketing automation platform. Organizations use it to coordinate cross-channel campaigns, manage customer databases, deliver personalized email services, and host public-facing web forms for engagement.

What does 'Eval Injection' mean for CVE-2026-48317?

This vulnerability is classified as Improper Neutralization of Directives in Dynamically Evaluated Code (CWE-95). It happens when the software processes user-provided data as if it were executable program instructions. In this instance, it allows an attacker to inject and run their own unauthorized commands on the server.

How can an attacker trigger this CVE-2026-48317 vulnerability?

An attacker needs low-level access to reach a specific administrative function that lacks proper input validation. Once that function is reached over the network, the code can be executed remotely. No human user needs to click a link or interact with the system for the flaw to trigger.

Is my Adobe Campaign Classic instance at risk?

According to Halo Surface Signal, this software is often deployed as an internet-facing application to support public-facing campaigns and web services. If your instance is reachable from the public internet, it falls into a high-visibility category that typically requires prioritized review.

Do I need to patch Adobe Campaign Classic immediately?

Your first step is to perform an inventory of all instances within your infrastructure. Confirm which systems are currently active and their specific network exposure. Once identified, coordinate with the platform owners to plan and implement remediation based on your organization's risk framework.

References