Executive brief
Adobe Campaign Classic, a marketing automation platform used for managing cross-channel customer campaigns, is affected by a critical security flaw. An attacker can exploit this vulnerability to bypass security controls and read sensitive files or memory from the server. This could lead to the exposure of confidential business data or system configuration details without requiring any interaction from a legitimate user.
Technical details
Adobe Campaign Classic (ACC) contains an SQL Injection vulnerability (CWE-89) due to improper neutralization of special elements used in SQL commands. The vulnerability is remotely exploitable over the network without authentication (PR:N) or user interaction (UI:N). Successful exploitation allows an attacker to read sensitive memory and gain unauthorized read access to the underlying file system. The vulnerability is notable for having a 'Changed' scope (S:C), indicating the impact extends beyond the immediate database environment to the host system. The issue is addressed in version 7.4.3 build 9398.
Affected products
- Adobe Campaign Classic (ACC) <= 7.4.3 build 9397
Timeline
- 2026-07-30: disclosed
- 2026-07-30: advisory