ZeroHour

CVE-2026-48381

moderate

Unauthenticated SQL Injection Leading to RCE in Adobe Campaign Classic

CVSS 3.1
9.0 critical
EPSS
<1%p46
Published
()
Modified
AI analysis

Adobe Campaign Classic contains an SQL injection flaw (CWE-89) that an attacker can leverage to execute arbitrary code in the context of the current user, with high confidentiality, integrity, and availability impact per Adobe's scoring. The flaw is reachable over the network without credentials (AV:N/PR:N) and requires no user interaction, but exploitation depends on conditions beyond the attacker's control (AC:H), and the changed scope (S:C) indicates the injected commands can affect resources beyond the vulnerable component. It affects organizations running Adobe Campaign Classic, Adobe's enterprise campaign-management platform, whose instances are typically deployed on-premises or in hybrid cloud setups. There is currently no public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS estimates roughly a 0.6% probability of exploitation within 30 days. Adobe has published a fix in its security bulletin, and the disclosure arrives alongside Adobe's recent batch of critical ColdFusion and Campaign Classic patches.

What to do: Upgrade all Campaign Classic instances to the fixed build cited in Adobe's security bulletin for CVE-2026-48381, checking the advisory for updated version details since exact ranges are not yet in this data. Prioritize any instances with internet-facing components (web applications, APIs, mid-source servers) and restrict network access to the platform until patched. Given the absence of a public exploit but the critical CVSS 9.0 score and code-execution potential, treat this as a high-priority, near-term patch rather than an emergency.

Affected
Adobe Campaign Classic (ACC)
Estimated exposure
moderateseveral thousand enterprise deployments (on the order of a few thousand organizations running ACC) — Adobe Campaign Classic is an enterprise marketing platform with a customer base on the order of a few thousand organizations, and its on-premises/hybrid deployment pattern means affected systems are likely in the low thousands rather than…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.

Vendors
adobe
Products
campaign
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Adobe patches seven flaws in ColdFusion, Commerce, and Campaign Classic, including actively exploited CVE-2026-71362 enabling customer account takeover.

Adobe issued Priority 1 updates fixing CVSS 10.0 flaws in ColdFusion (CVE-2026-48362, OS command injection) and Campaign Classic (CVE-2026-71398, CVE-2026-27302, incorrect authorization), plus CVE-2026-71362 (CVSS 9.1) in Adobe Commerce and Magento Open Source. Sansec reports threat actors are actively exploiting CVE-2026-71362 to switch customer sessions to other accounts and access private customer data. Adobe-hosted Campaign Classic instances are already remediated, while on-premise deployments are urged to patch within 72 hours. ColdFusion fixes ship in versions 2025.0.12 and 2023.0.23, and Campaign Classic fixes in v7 7.4.4 build 9400.

The Hacker News · Aug 15, 2026Vulnerability in the wildCVE-2026-48362CVE-2026-48273CVE-2026-71384+5 CVEs