External risk intelligence

Adobe Campaign Classic Code Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-48323

Adobe Campaign Classic is an enterprise marketing and campaign management platform that is commonly deployed as an internet-facing application or API to interact with external marketing assets, customer-facing web forms, and digital communication channels.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in Adobe Campaign Classic, a marketing and campaign management platform, could allow for arbitrary code execution. This issue does not require user interaction and has a broad impact, potentially affecting the confidentiality, integrity, and availability of systems.

  • Flaw in marketing software allows code to be run.
  • Could impact customer data and system operations.
  • Verify if this Adobe product is in use.

Attack Path

How an attacker could exploit the issue

An attacker could exploit a vulnerability in Adobe Campaign Classic by sending specially crafted data to the application. This could allow them to execute arbitrary code on the system hosting the application, potentially leading to a complete compromise of the affected component.

  • No special access required.
  • Specially crafted data triggers vulnerability.
  • Leads to arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Adobe Campaign Classic could allow an attacker to execute arbitrary code with the privileges of the current user. This could occur when a specially crafted template is processed, potentially leading to unauthorized actions on the affected system.

  • Arbitrary code execution.
  • Exploitation via network requests.
  • System compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Adobe Campaign Classic requires immediate attention from infrastructure and application teams. The first practical step is to inventory all ACC deployments, determine their external reachability and business criticality, identify the accountable system owner, and then prioritize remediation efforts.

  • Ownership: Infrastructure and application teams.
  • Verify first: External exposure and business criticality.
  • Action: Plan and execute remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Adobe Campaign Classic?

Adobe Campaign Classic is an enterprise-grade platform used by organizations to manage marketing campaigns, customer data, and digital communication channels. It functions as a central hub for orchestrating interactions across various media, often integrating with web forms and external marketing assets to deliver personalized customer experiences.

What does CWE-1336 mean for CVE-2026-48323?

CWE-1336 refers to Improper Neutralization of Special Elements Used in a Template Engine. In the context of this vulnerability, it means the software fails to correctly filter or handle data processed by its internal template engine. This flaw allows an attacker to inject and execute unauthorized commands, effectively tricking the system into running malicious code instead of legitimate template instructions.

How is CVE-2026-48323 triggered?

The vulnerability is triggered when the application processes specially crafted data sent via network requests. Because the flaw exists within the template engine's handling of input, it does not require a user to click a link or interact with the system. Simply sending the malicious data to an affected endpoint is sufficient to initiate the unintended code execution.

Is my Adobe Campaign Classic instance at risk?

According to Halo Surface Signal, this software is frequently deployed as an internet-facing application to interact with public-facing web forms and communication channels. Because the vulnerability is remotely exploitable, instances exposed to the internet are at a higher priority for review compared to those restricted to internal, isolated networks.

What should I do to address CVE-2026-48323?

Start by identifying all instances of Adobe Campaign Classic within your organization. Determine which systems are reachable from the internet and clarify who owns or manages each deployment. Once you have a complete inventory, coordinate with your infrastructure and application teams to evaluate the business impact and prioritize the necessary security updates.

References