External risk intelligence

Adobe Campaign Classic OS Command Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-82004

Adobe Campaign Classic is an enterprise marketing and campaign management platform that is frequently deployed as an internet-facing application to support web-based marketing activities, external web tracking, and public-facing campaign interactions.

OS Command Injection

Adobe Campaign

before 7.4.47.4.4

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical vulnerability in Adobe Campaign Classic that could allow an attacker to execute arbitrary code on affected systems without any user interaction. While the specific business impact depends on how the software is deployed and used within our organization, vulnerabilities of this nature generally pose a significant risk to system integrity and data security. Our primary concern is to confirm whether this technology is in use and assess any potential exposure.

  • Code execution vulnerability discovered in Adobe Campaign Classic.
  • Critical risk for system compromise if exploited.
  • Confirm relevance and potential exposure for our environment.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending a specially crafted request to Adobe Campaign Classic over the network. This request targets a component that improperly processes special characters, allowing the attacker to inject and execute operating system commands. If successful, arbitrary code can be executed with the privileges of the user running Adobe Campaign Classic, potentially leading to a compromise of the affected system.

  • No user interaction needed.
  • Vulnerable component processes commands.
  • Arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

When Adobe Campaign Classic is deployed in an internet-facing configuration, an attacker could exploit this vulnerability to execute arbitrary code on the affected system without user interaction, potentially impacting service behavior and system data.

  • System data and service behavior.
  • Unauthenticated network access.
  • Arbitrary code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Adobe Campaign Classic (ACC) likely impacts application owners and the infrastructure or platform teams responsible for its deployment and maintenance. The initial practical step is to identify all ACC instances, assess their exposure and criticality, locate the accountable system owner, and then develop a remediation plan based on that risk assessment.

  • Application and platform teams own remediation.
  • Verify ACC instance exposure and business criticality.
  • Plan remediation during a maintenance window.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Adobe Campaign Classic?

Adobe Campaign Classic is an enterprise-grade marketing and campaign management platform. Organizations use it to automate complex marketing workflows, manage customer databases, and coordinate multi-channel campaign interactions across email, web, and mobile environments.

What does this OS command injection vulnerability mean?

This vulnerability, classified as CWE-78, occurs when software fails to properly sanitize input before passing it to a system shell. In the context of CVE-2026-82004, it allows an unauthorized party to supply malicious data that the server interprets as a command, granting them the ability to execute unauthorized code with the privileges of the application.

How does an attacker trigger this CVE-2026-82004 vulnerability?

An attacker triggers this flaw by sending a specifically crafted network request to the Adobe Campaign Classic software. The vulnerability is triggered automatically by the way the application processes these inputs; notably, the exploit does not require any user interaction, such as clicking a link or opening a file, to succeed.

Is my Adobe Campaign Classic instance at risk?

Your risk level often depends on your network architecture. Halo Surface Signal notes that this platform is frequently deployed as an internet-facing application to support public-facing marketing activities. Instances exposed to the internet are more accessible to network-based attacks compared to those restricted to internal, private networks.

How should I respond to this Adobe Campaign Classic threat?

Your first step is to conduct a thorough inventory to locate all Adobe Campaign Classic deployments within your environment. Once identified, coordinate with the specific platform or infrastructure team responsible for each instance to assess its exposure and criticality, then prioritize a remediation plan according to your organization's maintenance schedule.

References