SQL Injection Vulnerability in Adobe Campaign Classic
CVE-2026-82009

9.1CRITICAL

Key Information:

Vendor

Adobe

Vendor
CVE Published:
22 September 2026

What is CVE-2026-82009?

Adobe Campaign Classic is susceptible to a vulnerability that stems from improper handling of special elements in SQL commands, allowing an attacker with elevated privileges to execute arbitrary SQL commands. This exploitation can occur without any user interaction, enabling unauthorized access and potential manipulation of database operations. Organizations utilizing Adobe Campaign Classic should implement recommended security patches and monitor their systems to mitigate the risk of exploitation.

Affected Version(s)

Adobe Campaign Classic 0 <= 7.4.4 build 9401

Adobe Campaign Classic 7.4.4 build 9402

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.