External risk intelligence

Adobe Campaign Classic SQL Injection Vulnerability Allows Security Feature Bypass

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-82011

Adobe Campaign Classic is an enterprise marketing automation platform frequently deployed as a web-based application to manage marketing campaigns, customer databases, and web-facing content, making it a common target for external network access in typical corporate environments.

SQL Injection

Adobe Campaign

7.4.3 and earlier7.4.4

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability in Adobe Campaign Classic allows a low-privileged attacker to bypass security controls and gain unauthorized access to data. The issue, an SQL injection flaw, could potentially enable an attacker to read and even modify sensitive information without requiring user interaction. The main concern is confirming if your Adobe Campaign Classic instances are affected and what data might be exposed.

  • Attackers can bypass security by injecting malicious SQL commands.
  • This could lead to unauthorized access to customer and campaign data.
  • Confirm relevance and exposure to understand potential risks.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this SQL injection vulnerability in Adobe Campaign Classic by sending specially crafted requests over the network. This could allow them to bypass security controls, gain unauthorized read access to data, and perform limited write operations, impacting the confidentiality and integrity of the system.

  • Requires network access and low privileges.
  • Triggered by improper SQL command neutralization.
  • Risks security bypass and data access.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Adobe Campaign Classic could allow a low-privileged attacker to bypass security controls. When successful, this bypass could grant unauthorized read and limited write access to system data. Exploitation does not require any interaction from a user.

  • System data and configuration at risk.
  • Unauthorized read and write access.
  • Security feature bypass.

Operational Fix

Recommended remediation, mitigation, and detection steps

This SQL injection vulnerability in Adobe Campaign Classic (ACC) impacts systems managed by either the application owners responsible for marketing automation or the infrastructure teams supporting the ACC deployment. The first practical step is to identify all ACC instances, determine their exposure to external networks, confirm business criticality, and assign an accountable owner before planning remediation.

  • Application or Infrastructure team ownership.
  • Confirm ACC instance exposure and criticality.
  • Plan risk-based remediation actions.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Adobe Campaign Classic?

Adobe Campaign Classic is an enterprise-grade marketing automation platform. Organizations use it to orchestrate complex marketing workflows, manage large-scale customer databases, and coordinate cross-channel content delivery. Because it integrates deeply with internal data systems and is often deployed as a web-based application, it serves as a central hub for managing sensitive customer information and campaign assets.

What does SQL injection mean for CVE-2026-82011?

This vulnerability is classified as CWE-89, or Improper Neutralization of Special Elements used in an SQL Command. In plain English, the software fails to properly filter user-supplied input before passing it to the database. An attacker can use this weakness to inject their own database queries, allowing them to manipulate the software's logic, bypass security checks, and unauthorizedly read or modify data.

How is this SQL injection vulnerability triggered?

An attacker triggers this bug by sending specially crafted network requests to the application. Because the software does not correctly sanitize these inputs, the backend executes the malicious commands. It is important to note that this process does not require any interaction from legitimate users, and the flaw cannot be triggered by simple, benign actions within the interface; it requires the specific, intentional injection of malicious SQL code.

Is my instance of Adobe Campaign Classic at risk?

According to Halo Surface Signal, this software is often deployed as a web-facing application, making it a common target for external network access. If your installation is accessible from the internet, the potential risk is significantly higher. You should assess whether your instances are reachable by unauthorized parties, as this vulnerability allows a low-privileged attacker to impact the system's security without needing further credentials or user assistance.

What should I do to address this vulnerability?

Your first step is to inventory all instances of Adobe Campaign Classic within your environment to understand their current network placement. Determine which systems are exposed to the internet versus those strictly internal. Once you have a clear map of your assets, identify the business owners for these systems, prioritize them by criticality, and prepare to implement the official security updates provided by the vendor.

References