Executive brief
Adobe Campaign Classic, a marketing automation and customer engagement platform, contains a code injection vulnerability that allows attackers to execute arbitrary code on the server without requiring user interaction. An attacker can exploit this to gain full control over the Campaign Classic instance, access customer data, modify campaigns, or pivot to other systems.
Technical details
Improper control of code generation in Campaign Classic allows code injection attacks that result in arbitrary code execution in the context of the application. The vulnerability can be exploited remotely without user interaction or prior authentication, indicating a pre-authentication attack surface.
Affected products
- Adobe Campaign Classic
Timeline
- 2026-09-22: disclosed