SQL Injection Vulnerability in Adobe Campaign Classic
CVE-2026-82011

9.1CRITICAL

Key Information:

Vendor

Adobe

Vendor
CVE Published:
22 September 2026

What is CVE-2026-82011?

Adobe Campaign Classic is impacted by an SQL injection vulnerability that allows attackers to bypass security features. A low-privileged attacker could exploit this flaw to gain unauthorized access to read sensitive data and execute limited write operations. Notably, this exploit does not require any user interaction, thereby increasing the risk of unauthorized data manipulation. Organizations using Adobe Campaign Classic should take immediate action to address this vulnerability and ensure data integrity and security.

Affected Version(s)

Adobe Campaign Classic 0 <= 7.4.4 build 9401

Adobe Campaign Classic 7.4.4 build 9402

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.