External risk intelligence

Adobe Campaign Classic SQL Injection Leading to Code Execution.

CVE advisorySeverity: CRITICAL (CVSS 9.0)

CVE-2026-48381

Adobe Campaign Classic is an enterprise marketing and campaign management platform often deployed as an internet-facing web application to facilitate external marketing communications, tracking, and web-based campaign management.

SQL Injection

Adobe Campaign

7.2.1 to before 7.4.4

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical security vulnerability in Adobe Campaign Classic, a platform used for marketing and campaign management. The vulnerability, if exploited under specific conditions, could allow an attacker to execute arbitrary code on affected systems. The main concern is to confirm if this technology is in use and assess any potential exposure.

  • A coding flaw may allow unauthorized code execution.
  • This affects critical marketing and campaign management systems.
  • Confirm use and assess exposure to this potential risk.

Attack Path

How an attacker could exploit the issue

An attacker could potentially exploit this SQL injection vulnerability in Adobe Campaign Classic by sending specially crafted input to the application. If successful, this could allow them to execute arbitrary code with the privileges of the current user, potentially leading to a compromise of the application's environment. Exploiting this vulnerability depends on conditions outside the attacker's direct control and does not require any action from a user.

  • No authentication required.
  • Attacker sends malicious SQL input.
  • Arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Adobe Campaign Classic could allow an attacker to execute arbitrary code on the system when specific, uncontrolled conditions are met. This could potentially impact the confidentiality, integrity, and availability of the affected system.

  • System data and service behavior could be affected.
  • Malicious SQL commands could be injected.
  • Arbitrary code execution may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

This SQL injection vulnerability in Adobe Campaign Classic (ACC) likely requires coordination between application owners responsible for ACC and potentially infrastructure or platform teams supporting its deployment. The first practical step is to identify all ACC instances, confirm their external reachability and business criticality, and then assign ownership for remediation planning.

  • Application owners should confirm exposure.
  • Verify all ACC instances are inventoried.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Adobe Campaign Classic?

Adobe Campaign Classic is an enterprise-grade platform designed for managing marketing campaigns, orchestrating customer communications, and handling data-driven marketing tasks. It serves as a centralized hub for organizations to track engagement and automate marketing workflows across various digital channels.

What does CVE-2026-48381 mean for software security?

This vulnerability is an Improper Neutralization of Special Elements used in an SQL Command, commonly known as SQL Injection (CWE-89). It means the software does not properly filter user-provided input before using it in database queries. In this case, that weakness allows an attacker to potentially execute their own malicious code on the system.

How does an attacker trigger this vulnerability?

An attacker triggers this by sending specially crafted input to the application that manipulates underlying SQL commands. It is important to note that the vulnerability does not trigger through standard user interaction; it requires specific, complex environmental conditions that remain outside of the attacker's direct control to succeed.

Why should I care about CVE-2026-48381?

You should care because Halo Surface Signal identifies Adobe Campaign Classic as a platform frequently deployed as an internet-facing web application. Because it is often accessible from the public internet to manage external communications and tracking, it may be reachable by unauthorized parties, increasing the potential risk to your environment.

Do I need to take action if I use Adobe Campaign Classic?

Yes. Your first step is to inventory all instances of Adobe Campaign Classic within your organization. Once identified, coordinate with the teams that own and support these applications to assess their internet connectivity and business criticality, which will help you prioritize and plan the necessary remediation steps.

References