Description
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-08-11
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Campaign Classic is vulnerable to improper neutralization of special elements in an SQL command, resulting in a classic SQL injection flaw. The flaw can allow an attacker to inject and execute arbitrary SQL, which is capable of being leveraged to run arbitrary code within the context of the current user. The impact is therefore the potential for remote code execution, with the risk that an attacker could use the injection to alter data or compromise the underlying system.

Affected Systems

The affected product is Adobe Campaign Classic from Adobe. No specific version information is listed in the CNA data, so all released versions of the product are potentially at risk until the vendor issues a fix.

Risk and Exploitability

The CVSS score of 9 indicates a high severity flaw. The EPSS score is less than 1%, suggesting that the probability of exploitation in the wild is low but not zero. The vulnerability is not listed in CISA's KEV catalog. Although exploitation does not require user interaction, the attack vector is inferred to be through the web interface of the product, which accepts user-supplied input that is incorporated into database queries. The "Scope changed" qualifier implies that the attacker could gain privileges beyond the current user if exploitation is successful.

Generated by OpenCVE AI on August 12, 2026 at 20:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Adobe's security advisory (APSb26-123) for the latest patch and apply it immediately.
  • Reconfigure the application to use parameterized queries or an ORM that avoids raw SQL string concatenation.
  • Enforce the principle of least privilege on the database account used by Adobe Campaign Classic.

Generated by OpenCVE AI on August 12, 2026 at 20:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe campaign
CPEs cpe:2.3:a:adobe:campaign:*:*:*:*:classic:*:*:*
Vendors & Products Adobe campaign

Thu, 13 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe campaign Classic
Vendors & Products Adobe
Adobe campaign Classic

Tue, 11 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.
Title Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Campaign Campaign Classic
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:34:10.593Z

Reserved: 2026-05-21T15:28:38.142Z

Link: CVE-2026-48381

cve-icon Vulnrichment

Updated: 2026-08-11T18:55:33.630Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T18:17:28.247

Modified: 2026-08-28T00:17:56.293

Link: CVE-2026-48381

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:30:04Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')