External risk intelligence

Adobe Campaign Classic SQL Injection Leading to Code Execution.

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-48330

Adobe Campaign Classic is an enterprise marketing and campaign management platform often deployed as a web-accessible application to support external interactions, landing pages, and API integrations, making it a common target for internet-facing service exposure.

SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

Adobe Campaign Classic is impacted by a critical vulnerability that could allow unauthorized execution of commands within the application. This issue, identified as SQL Injection, does not require user interaction and could lead to elevated access or control. The main concern is to confirm if this specific Adobe product is in use and if it is exposed to external networks.

  • Unauthorized code execution in Adobe software.
  • Potential for significant unauthorized access or control.
  • Verify product usage and exposure for risk assessment.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending specially crafted SQL commands over the network to Adobe Campaign Classic. This bypasses the need for any prior access or user interaction, allowing the attacker to directly target the vulnerable component. Successful exploitation can lead to the execution of arbitrary SQL commands, potentially resulting in elevated privileges and control over the application.

  • No privileges or user interaction needed.
  • SQL injection in SQL commands.
  • Arbitrary code execution and elevated access.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to execute arbitrary SQL commands by sending specially crafted requests to Adobe Campaign Classic. If successful, this could lead to unauthorized access and modification of application data, or potentially alter the application's behavior and gain elevated privileges within the application's context.

  • Application data and configuration
  • Via specially crafted network requests
  • Unauthorized access and control

Operational Fix

Recommended remediation, mitigation, and detection steps

This SQL injection vulnerability in Adobe Campaign Classic requires immediate attention from application owners and infrastructure teams responsible for its operation. The first step is to determine the specific instances of Adobe Campaign Classic within your environment, assess their external reachability and business criticality, and identify the accountable teams for remediation. Subsequent actions will depend on this initial assessment and risk analysis.

  • Identify and confirm accountable owners.
  • Verify external exposure and business criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Adobe Campaign Classic?

Adobe Campaign Classic is an enterprise-grade platform designed for managing marketing campaigns, customer data, and cross-channel communications. Organizations use it to build automated workflows, personalize customer interactions, and host web-based components like landing pages or APIs that connect with external audiences.

What does SQL injection mean for CVE-2026-48330?

This vulnerability is classified as CWE-89, or Improper Neutralization of Special Elements used in an SQL Command. Essentially, the application fails to properly sanitize input, allowing an attacker to inject and execute their own database commands. In this specific case, it can escalate to arbitrary code execution, granting the attacker control over the application environment.

How can an attacker trigger this vulnerability?

An attacker triggers this flaw by sending specially crafted network requests directly to the Adobe Campaign Classic application. Because the system does not require any prior authentication or user interaction, the attack path is highly direct. It is important to note that this is a network-based issue; simply visiting the site as a regular user does not trigger the bug.

Why should I care if my instance is internet-facing?

Halo Surface Signal indicates that Adobe Campaign Classic is often deployed as a web-accessible application for external marketing interactions, making internet-facing instances a likely target. If your installation is exposed to the public internet, it can be reached by unauthorized actors without internal network access, significantly increasing the risk.

Do I need to update my Adobe Campaign Classic instance?

Your first step is to locate all instances of the software within your environment and determine their business criticality and external reachability. Once you have identified these assets, coordinate with the accountable team to verify your exposure and prepare for the necessary security updates or configuration changes provided by the vendor.

References