SQL Injection Vulnerability in Adobe Campaign Classic
CVE-2026-48448

8.6HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
30 July 2026

What is CVE-2026-48448?

Adobe Campaign Classic is susceptible to an SQL Injection vulnerability due to improper neutralization of special elements within SQL commands. This security flaw may allow attackers to access sensitive data stored in the system by leveraging file system read access without any user interaction required. It is crucial for users to review their implementations and apply necessary patches to mitigate this risk.

Affected Version(s)

Adobe Campaign Classic 0 <= 7.4.3 build 9397

Adobe Campaign Classic 0 <= 7.4.3 build 9397

Adobe Campaign Classic 7.4.3 build 9398

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.