Executive brief
Adobe Campaign Classic is an enterprise marketing automation platform used to manage customer campaigns and communications. A vulnerability in input validation allows a low-privileged attacker to execute arbitrary code within the application, potentially compromising the marketing data, customer information, and operations managed by the platform. No user interaction is required to exploit this vulnerability.
Technical details
An improper input validation flaw in Adobe Campaign Classic allows a low-privileged attacker to achieve arbitrary code execution in the context of the current user. The vulnerability has changed scope and does not require user interaction for exploitation, though successful exploitation depends on certain conditions beyond the attacker's control. A fix is expected to be available from Adobe.
Affected products
- Adobe Campaign Classic
Timeline
- 2026-09-22: disclosed