Executive brief
Adobe Campaign Classic, a marketing automation and campaign management platform, contains a code injection flaw that allows attackers to execute arbitrary code with the privileges of the application. An attacker can exploit this vulnerability remotely without requiring user interaction or authentication, potentially giving them full control over the Campaign instance and access to sensitive marketing and customer data.
Technical details
Adobe Campaign Classic is vulnerable to improper control of code generation (CWE-94), allowing arbitrary code injection and execution in the context of the application. The vulnerability is network-accessible, requires no authentication or user interaction, and grants an unauthenticated attacker the ability to execute arbitrary code with the application's privileges, potentially compromising the entire Campaign infrastructure and data.
Affected products
- Adobe Campaign Classic
Timeline
- 2026-09-22: disclosed