Junglewise Threat Intelligence

CVE-2026-76195: Adobe Campaign Classic OS command injection

CVE-2026-76195 · Severity: critical · CVSS 10 · Published 2026-08-25

Technologies: Microsoft Windows, Linux Kernel, Adobe Campaign Classic. Vendors: Microsoft, Linux, Adobe.

Executive brief

Adobe Campaign Classic is an enterprise marketing automation platform used by organizations to manage customer communications and campaigns. This OS command injection vulnerability allows an attacker to execute arbitrary code on the server without requiring user interaction, potentially leading to complete system compromise and unauthorized access to sensitive customer data and campaign information.

Technical details

The vulnerability is an improper neutralization of special elements in OS commands (CWE-78: OS Command Injection) in Adobe Campaign Classic. The root cause involves insufficient input validation or output encoding of user-supplied data before passing it to system command execution functions. An attacker can craft malicious input containing shell metacharacters to break out of the intended command context and inject arbitrary OS commands. No user interaction is required for exploitation, and the scope is changed, indicating the impact extends beyond the vulnerable component. The attacker can achieve arbitrary code execution in the context of the process running Campaign Classic.

Affected products

  • Adobe Campaign Classic <UNKNOWN>

Timeline

  • 2026-08-25: disclosed

References

Related threats