External risk intelligence

Adobe Campaign Classic SQL Injection Leads to Code Execution.

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-82010

Adobe Campaign Classic is an enterprise marketing automation platform frequently deployed as a web-accessible application to facilitate external marketing campaigns, landing pages, and email tracking, making its web-facing interfaces commonly reachable from the internet.

SQL Injection

Adobe Campaign

7.4.3 and earlier7.4.4

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

Adobe Campaign Classic is affected by a critical vulnerability that could allow a low-privileged attacker to execute arbitrary code. This means an attacker could potentially take control of systems running the software without any action from a user.

  • SQL injection flaw impacts Adobe Campaign.
  • Allows attackers to run unauthorized code.
  • Confirm relevance and exposure of Adobe Campaign Classic.

Attack Path

How an attacker could exploit the issue

An attacker with low-level access could target Adobe Campaign Classic by sending specially crafted SQL commands. This vulnerability exists within the application's handling of user input, allowing an attacker to manipulate database queries. If successful, this could lead to the execution of arbitrary code on the system.

  • Requires low-privileged access.
  • Triggers via crafted SQL commands.
  • Leads to arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Adobe Campaign Classic could allow a low-privileged attacker to execute arbitrary code on the system. The attack does not require user interaction and can change the scope, potentially affecting system integrity and availability.

  • Arbitrary code execution.
  • SQL injection via network access.
  • System compromise and data manipulation.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-world responsibility for addressing this SQL injection vulnerability in Adobe Campaign Classic (ACC) likely falls to the platform or application owner teams responsible for its deployment and maintenance. The first practical step is to identify all ACC instances, confirm their exposure and criticality, and then coordinate with the vendor and relevant internal teams to plan remediation during a suitable maintenance window.

  • Platform and application owners should take ownership.
  • Verify ACC instance exposure and criticality.
  • Plan remediation with vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Adobe Campaign Classic?

Adobe Campaign Classic is an enterprise-grade marketing automation platform. Organizations use it to manage multi-channel marketing campaigns, design landing pages, track email engagement, and coordinate complex customer communications across digital platforms.

What does CVE-2026-82010 mean by SQL injection?

This CVE involves a weakness known as CWE-89, or Improper Neutralization of Special Elements used in an SQL Command. Essentially, the software fails to properly sanitize user input, allowing an attacker to inject their own malicious SQL commands into database queries. In this case, the vulnerability is severe enough that it can escalate into the execution of unauthorized, arbitrary code on the underlying system.

How is this vulnerability triggered?

An attacker triggers this flaw by sending specially crafted SQL commands to the application. It is important to note that this attack does not require any interaction from legitimate users to succeed. However, this does not mean the system is vulnerable to random background traffic; the attacker must have at least low-privileged access to the application to deliver the malicious input effectively.

Is my Adobe Campaign Classic instance at risk?

Halo Surface Signal indicates that Adobe Campaign Classic is often deployed as a web-accessible application to handle public-facing marketing tasks. Because these interfaces are frequently reachable from the internet, they are often exposed to network-based attacks. You should care about this if your instance is internet-facing or handles sensitive data, as the vulnerability allows for remote exploitation.

What are the first steps to address this CVE?

The immediate priority is to identify all instances of Adobe Campaign Classic within your environment. Once identified, evaluate the specific deployment context to determine its exposure. Coordinate with your security and platform teams to review the vendor's guidance and schedule the necessary updates or patches during an upcoming maintenance window.

References