ZeroHour

CVE-2026-82004

moderate1

Unauthenticated OS Command Injection in Adobe Campaign Classic

CVSS 3.1
10.0 critical
EPSS
1%p72
Published
()
Modified
AI analysis

Adobe Campaign Classic (ACC) contains an OS command injection flaw (CWE-78) in which special elements passed to an operating system command are improperly neutralized, allowing attacker-supplied commands to run on the host. Per the CVSS vector, it is reachable over the network (AV:N), requires no privileges or user interaction, and has changed scope (S:C), meaning a successful attack can also affect resources beyond the vulnerable component. An attacker gains arbitrary code execution in the context of the current user, with high impact to confidentiality, integrity, and availability. Any organization running an affected Adobe Campaign Classic deployment is potentially exposed, though only instances reachable over the network are practically exploitable. No public proof-of-concept or confirmed in-the-wild exploitation is known, EPSS estimates a ~1.4% probability of exploitation within 30 days, and the fix arrived in a large Adobe patch release covering 170+ vulnerabilities.

What to do: Upgrade Campaign Classic to the fixed build listed in Adobe's security bulletin for this CVE, since the affected and fixed version numbers are not included in the data provided. Until patched, limit network exposure of Campaign Classic application/web servers to trusted networks, as the flaw is exploitable without authentication or user interaction. Monitor for a public PoC or CISA KEV listing and review application service accounts for signs of unexpected command execution.

Affected
Adobe Campaign Classic (ACC)
Estimated exposure
moderate~1,000-10,000 enterprise deployments worldwide (estimate; Adobe publishes no install counts) — Adobe Campaign Classic is an enterprise marketing platform used primarily by large organizations, typically with a handful of servers per customer, which implies an installed base in the thousands of deployments; no public active-install…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Vendors
adobe
Products
campaign
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

Adobe patched over 170 flaws, including in-the-wild zero-day CVE-2026-75650 (CVSS 10) in Adobe Commerce/Magento enabling unauthenticated RCE and web shell deployments.

Adobe released fixes for more than 170 vulnerabilities across Experience Manager, Acrobat Reader, Photoshop and other products. The Commerce zero-day CVE-2026-75650 (CVSS 10) allows unauthenticated code injection leading to remote code execution and has been exploited since September 4. Sansec reported multiple threat actors deploying backdoors and web shells via the bug, dubbed StyleSmuggler, which triggers injected code through Magento's Payment Transaction Failed Reminder email. Adobe also patched critical Campaign Classic command injection CVE-2026-82004 and two critical ColdFusion RCE flaws (CVE-2026-48273, CVE-2026-75746).

SecurityWeek · 7d agoExploit / PoC in the wildCVE-2026-75650CVE-2026-82004CVE-2026-48273+1 CVEs1