Executive brief
Adobe Campaign Classic, a marketing automation platform, contains a SQL injection vulnerability that allows attackers with low-level access to bypass security controls and read or modify data without authorization. An attacker can exploit this flaw remotely without requiring user interaction, potentially exposing sensitive customer data or campaign information stored in the platform.
Technical details
SQL injection in Adobe Campaign Classic allows a low-privileged authenticated attacker to inject arbitrary SQL commands, bypassing application-level security controls. The vulnerability requires network access and prior authentication but does not require user interaction; exploitation grants unauthorized read access and limited write capabilities with changed scope. This is a classic improper input neutralization issue where special SQL characters are not properly sanitized before query execution.
Affected products
- Adobe Campaign Classic
Timeline
- 2026-09-22: disclosed