External risk intelligence

Adobe Campaign Classic Arbitrary Code Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-82008

Adobe Campaign Classic is an enterprise marketing automation platform frequently deployed as an internet-facing web application to manage marketing campaigns, customer data, and communication workflows, making its components often reachable via the internet in standard business deployments.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects Adobe Campaign Classic, a platform for managing marketing campaigns. It allows a low-privileged attacker to execute arbitrary code without user interaction, potentially impacting the integrity and availability of systems. The main concern is confirming relevance and exposure within your environment.

  • Input validation flaw allows code execution.
  • Critical severity impacts business operations.
  • Assess relevance and exposure urgently.

Attack Path

How an attacker could exploit the issue

An attacker with low privileges could leverage this improper input validation flaw in Adobe Campaign Classic to achieve arbitrary code execution. The attacker would not need user interaction to exploit this vulnerability, and the scope of the impact changes, potentially allowing for significant compromise of the system.

  • Low-privileged access is required.
  • Vulnerable input validation can be triggered remotely.
  • Enables arbitrary code execution and scope change.

Live Threat

Current exploitation, exposure, and threat context

An Improper Input Validation vulnerability in Adobe Campaign Classic could allow a low-privileged attacker to execute arbitrary code on the system in the context of the current user, without requiring any user interaction. This could potentially impact the confidentiality, integrity, and availability of the affected system.

  • System code and data execution.
  • Remote unauthenticated code injection.
  • Compromise of system integrity and data.

Operational Fix

Recommended remediation, mitigation, and detection steps

Adobe Campaign Classic (ACC) is an enterprise marketing platform that, when deployed externally, may require coordination between application owners, infrastructure teams, and security operations. The first practical step is to confirm the ACC deployment's reachability and business criticality, identify the accountable owner, and then prioritize remediation based on risk.

  • Application and infrastructure teams own the issue.
  • Verify external accessibility and critical systems.
  • Plan remediation based on confirmed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Adobe Campaign Classic?

Adobe Campaign Classic is an enterprise-grade marketing automation platform. Organizations use it to orchestrate complex customer journeys, manage large-scale marketing databases, and automate cross-channel communication workflows like email, SMS, and direct mail campaigns.

What does CVE-2026-82008 mean for security?

This vulnerability is an Improper Input Validation flaw, categorized as CWE-20. It means the software does not sufficiently check or sanitize data provided by users before processing it. In this case, that weakness allows an attacker to inject and execute their own unauthorized code on the system, taking control in the context of the current user.

How is this vulnerability triggered?

An attacker with low-level, authenticated access can trigger this flaw by sending specially crafted input to the application. It does not require any interaction from a legitimate user to succeed. Notably, the vulnerability is not triggered by standard, expected user activities but rather by malicious payloads that bypass the system's input checks.

Why should I care about this CVE?

Halo Surface Signal indicates that Adobe Campaign Classic is frequently deployed as an internet-facing application, making it reachable by external actors. Because the vulnerability allows for remote arbitrary code execution, any instance accessible from the public internet carries a significantly higher risk of compromise than those limited to internal networks.

How do I respond to this threat?

Your first step is to locate your instances of Adobe Campaign Classic and confirm their network accessibility. Coordinate with your application and infrastructure teams to determine if your specific version is affected. Once you have identified the accountable owners for these systems, prioritize the installation of vendor-provided security updates to mitigate the risk.

References