Executive brief
Adobe Campaign Classic, a marketing automation and customer engagement platform used by enterprises, contains a code injection vulnerability that allows attackers to execute arbitrary code with the privileges of the current user. An attacker can exploit this vulnerability remotely without requiring user interaction, potentially compromising sensitive campaign data, customer information, and business operations.
Technical details
An improper control of code generation flaw in Adobe Campaign Classic allows unauthenticated network-based code injection and arbitrary code execution in the context of the current user. The vulnerability requires no authentication or user interaction, indicating a network-accessible attack surface with direct impact to confidentiality, integrity, and availability.
Affected products
- Adobe Campaign Classic
Timeline
- 2026-09-22: disclosed