Junglewise Threat Intelligence

CVE-2026-82009: Adobe Campaign Classic SQL injection

CVE-2026-82009 · Severity: critical · CVSS 9.1 · Published 2026-09-22

Technologies: Microsoft Windows, Linux Kernel, Adobe Campaign Classic. Vendors: Microsoft, Linux, Adobe.

Executive brief

Adobe Campaign Classic, a customer relationship management platform used for marketing automation and campaign management, is vulnerable to SQL injection attacks. An attacker with elevated privileges can execute arbitrary SQL commands to manipulate or extract data from the database, potentially compromising customer records and business operations without any user interaction required.

Technical details

An improper neutralization of special characters in SQL commands allows a high-privilege attacker to inject malicious SQL code and execute arbitrary commands within the database context of the application. The vulnerability requires the attacker to already possess elevated privileges and has a changed security scope indicating potential privilege escalation or impact boundary modifications. No user interaction is necessary to exploit this flaw.

Affected products

  • Adobe Campaign Classic

Timeline

  • 2026-09-22: disclosed

References

Related threats