External risk intelligence

Adobe Campaign Classic Code Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-89276

Adobe Campaign Classic is an enterprise marketing automation platform frequently deployed as a web-accessible application to manage campaigns, customer data, and external-facing marketing communications, often requiring network-accessible interfaces for operation.

Code Injection

Adobe Campaign

7.4.3 and earlier7.4.4

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

Adobe Campaign Classic is affected by a critical code injection vulnerability that could allow a low-privileged attacker to execute arbitrary code remotely without user interaction. This could potentially impact the integrity and availability of systems managing customer data and marketing communications.

  • Attackers can run unauthorized code.
  • Affects marketing automation and customer data systems.
  • Confirm if this critical risk applies to us.

Attack Path

How an attacker could exploit the issue

An attacker with low privileges could leverage this vulnerability by reaching a specific feature within Adobe Campaign Classic that is susceptible to improper control of code generation. This could allow them to execute arbitrary code on the system without requiring any interaction from a user, potentially leading to significant compromise.

  • Low-privileged access is sufficient.
  • Code injection in a vulnerable feature.
  • Arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Adobe Campaign Classic could allow a low-privileged attacker to execute arbitrary code without user interaction, potentially impacting the confidentiality, integrity, and availability of the system.

  • System code and data.
  • Via network access.
  • Arbitrary code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Adobe Campaign Classic impacts application owners and the platform team responsible for its deployment and maintenance. The immediate first step is to locate all instances of Adobe Campaign Classic, determine their business criticality and external reachability, and identify the specific system owners. Remediation planning should then be risk-based.

  • Application owners should lead remediation efforts.
  • Verify all Adobe Campaign Classic instances.
  • Plan remediation with vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Adobe Campaign Classic?

Adobe Campaign Classic is an enterprise-grade marketing automation platform. Organizations use it to orchestrate complex marketing campaigns, manage large-scale customer databases, and automate multi-channel communications. It acts as a central hub for data-driven marketing, often integrating with various business systems to deliver personalized content.

How does CVE-2026-89276 allow code injection?

This vulnerability is classified as Improper Control of Generation of Code (CWE-94). It means the software does not correctly sanitize or validate input before using it to generate or execute instructions. By sending specific, malformed input, an attacker can trick the system into running their own unauthorized commands in the context of the currently logged-in user.

Do I need to click anything to trigger this vulnerability?

No, user interaction is not required to trigger this flaw. The attack is successful simply if the attacker can reach the vulnerable feature through the network. It is not triggered by normal administrative tasks or legitimate marketing activities, but rather through specifically crafted malicious requests sent to the affected service.

Is my instance at risk according to Halo Surface Signal?

Halo Surface Signal identifies Adobe Campaign Classic as a likely candidate for external-facing exposure because it is typically deployed as a web-accessible application. Since it requires network interfaces to manage external marketing communications and data, it is often reachable via the internet, which increases the likelihood that a remote attacker could reach this vulnerability.

What should I do first to manage this risk?

Begin by auditing your environment to locate every running instance of Adobe Campaign Classic. Once identified, determine which instances are accessible via the network and assign them to the relevant system owners. Prioritize these systems based on their business criticality and exposure level, and coordinate with the vendor to plan the necessary updates or security configurations.

References