External risk intelligence

Adobe Campaign Classic SQL Injection Vulnerability Allows Arbitrary Code Execution.

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-48326

Adobe Campaign Classic is an enterprise marketing automation platform. While typically deployed within internal or restricted corporate network segments to manage customer data and campaigns, it may be reachable from the internet in some deployments to facilitate web-based marketing integrations, making external exposure possible but not the default or standard design for all components.

SQL Injection

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical vulnerability in Adobe Campaign Classic, an enterprise marketing automation platform. The issue involves SQL injection, which could allow a low-privileged attacker to execute arbitrary code with the user's permissions. This could have significant implications for data security and system control if exploited.

  • Affects marketing platform, enabling code execution.
  • Critical flaw could compromise user context and data.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker with low privileges could exploit this SQL injection vulnerability in Adobe Campaign Classic by sending a specially crafted request. This could allow them to execute arbitrary code on the system, potentially leading to a compromise of the affected user's context. The attack does not require any action from a user.

  • Low-privileged access required.
  • SQL injection vulnerability triggered.
  • Arbitrary code execution possible.

Live Threat

Current exploitation, exposure, and threat context

An SQL injection vulnerability in Adobe Campaign Classic could allow a low-privileged attacker to execute arbitrary code on the system. This could occur when supported by the advisory's conditions, potentially affecting system operations and data integrity, as the attacker could execute code within the context of the current user.

  • System code execution.
  • Via network when supported.
  • Unauthorized system access.

Operational Fix

Recommended remediation, mitigation, and detection steps

Adobe Campaign Classic (ACC) requires immediate attention due to a critical SQL injection vulnerability that could allow a low-privileged attacker to execute arbitrary code. Given ACC's role in managing sensitive customer data and marketing operations, the application owners and infrastructure teams are likely responsible for addressing this. The first critical step is to identify all ACC instances, confirm their network exposure and business criticality, and then engage the accountable owner to plan a risk-based remediation strategy.

  • Application owners must manage the issue.
  • Verify ACC instance exposure and criticality first.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Adobe Campaign Classic?

Adobe Campaign Classic is an enterprise marketing automation platform designed to manage customer data, organize complex marketing workflows, and execute cross-channel campaigns. It acts as a centralized hub for businesses to coordinate customer interactions, making it a critical repository for sensitive audience information and campaign assets that require restricted access.

What does SQL injection mean for CVE-2026-48326?

This vulnerability, classified as CWE-89, happens when the software fails to properly sanitize input before using it in a database query. For this CVE, that weakness allows an attacker to manipulate SQL commands. Because the system runs these queries, the flaw can be leveraged to execute unauthorized code, effectively letting the attacker act within the system using the permissions of the current user.

How is this Adobe Campaign Classic bug triggered?

An attacker with low-level privileges triggers this by sending a specifically crafted request to the application. The vulnerability does not require the target user to click anything or perform any action. Notably, simple access or legitimate usage of the platform's standard marketing features does not initiate the flaw; it requires the deliberate injection of malicious command strings.

Is my Adobe Campaign Classic instance at risk?

According to Halo Surface Signal, this software is typically kept on internal or restricted networks. However, because some organizations connect it to the internet for web-based marketing integrations, external exposure is possible. You should determine if your specific deployment is reachable from the internet or if it is strictly segmented within your private corporate network.

How should I respond to CVE-2026-48326?

Begin by creating an inventory of all Adobe Campaign Classic instances running in your environment. Once identified, verify which systems are internet-facing versus those on internal segments to prioritize your efforts. Consult the official security documentation provided by Adobe to understand the specific update path and engage your system owners to coordinate a risk-based remediation plan.

References