Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.0
CVE-2026-48381: Adobe Campaign Classic | Malicious SQL Code Execution Risk
CVE-2026-48381
CVE-2026-48381
Summary
Adobe Campaign Classic is affected by a security flaw that could allow an attacker to execute malicious code on a server. This could lead to unauthorized access or data theft. Adobe and other vendors are working to fix the issue, and users should wait for a patch before taking action.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| adobe | adobe campaign classic | <= ACC v7: 7.4.3 build 9399 |
Original title
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Original description
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.
nvd CVSS3.1
9.0
Vulnerability type
CWE-89
SQL Injection
Published: 11 Aug 2026 · Updated: 11 Aug 2026 · First seen: 11 Aug 2026