Junglewise Threat Intelligence

CVE-2026-48381: Adobe Campaign Classic SQL injection

CVE-2026-48381 · Severity: critical · CVSS 9 · Published 2026-08-11

Technologies: Adobe Campaign Classic. Vendors: Adobe.

Executive brief

Adobe Campaign Classic is an enterprise email marketing and customer relationship management platform used to manage customer communications. A SQL injection vulnerability allows attackers to execute arbitrary code within the application's context without requiring user interaction, potentially compromising sensitive marketing data and customer information managed by the platform.

Technical details

Adobe Campaign Classic contains an SQL injection vulnerability in improper neutralization of special elements used in SQL commands. The vulnerability allows an attacker to inject arbitrary SQL code, leading to arbitrary code execution in the context of the current user. No user interaction is required for exploitation, though successful exploitation depends on conditions beyond the attacker's control. The attack vector is network-based, and the scope is changed (impact extends beyond the affected component).

Affected products

  • Adobe Campaign Classic

Timeline

  • 2026-08-11: disclosed

References

Related threats