Junglewise Threat Intelligence

CVE-2026-82008: Adobe Campaign Classic improper input validation

CVE-2026-82008 · Severity: critical · CVSS 9.9 · Published 2026-09-22

Technologies: Microsoft Windows, Linux Kernel, Adobe Campaign Classic. Vendors: Microsoft, Linux, Adobe.

Executive brief

Adobe Campaign Classic, a marketing automation platform used to manage customer campaigns and communications, contains an input validation flaw that could allow an attacker with low privileges to execute arbitrary code on the server. An attacker could exploit this vulnerability to gain control of the campaign system without needing the victim to interact with a malicious link or file, potentially compromising customer data and business operations.

Technical details

The vulnerability is an improper input validation flaw in Adobe Campaign Classic that permits arbitrary code execution within the current user context. A low-privileged attacker can exploit this remotely without user interaction, and the impact includes privilege escalation due to scope change as documented in the advisory.

Affected products

  • Adobe Campaign Classic

Timeline

  • 2026-09-22: disclosed

References

Related threats