Executive brief
Adobe Campaign Classic, a marketing automation and customer data platform used by enterprises, contains a code injection flaw that allows an attacker to execute arbitrary code with the privileges of the affected user. An attacker can exploit this vulnerability remotely without requiring any user interaction, potentially gaining control over the application and accessing sensitive customer data or campaign information.
Technical details
This is an improper control of code generation (CWE-94) vulnerability in Adobe Campaign Classic that enables arbitrary code execution in the context of the current user. The vulnerability is network-exploitable without authentication or user interaction required, and impacts system confidentiality, integrity, and availability with changed scope.
Affected products
- Adobe Campaign Classic
Timeline
- 2026-09-22: disclosed