Executive brief
Adobe Campaign Classic is a marketing automation platform used by enterprises to design and execute customer campaigns. A critical command injection vulnerability allows an attacker to execute arbitrary code with the privileges of the Campaign service, potentially compromising customer data, campaign execution, and the integrity of the entire marketing platform without requiring user interaction.
Technical details
The vulnerability is an OS command injection (CWE-78) flaw in Adobe Campaign Classic where special characters in user-supplied input are not properly neutralized before being passed to OS command execution. An unauthenticated or network-adjacent attacker can inject arbitrary OS commands that execute in the security context of the Campaign service process. The scope change indicates the vulnerability can impact resources beyond the vulnerable component itself. Patches are expected from Adobe; check APSB26-142 advisory for patched versions.
Affected products
- Adobe Campaign Classic
Timeline
- 2026-09-08: disclosed