Code Injection Vulnerability in Adobe Campaign Classic
CVE-2026-89275

10CRITICAL

Key Information:

Vendor

Adobe

Vendor
CVE Published:
22 September 2026

What is CVE-2026-89275?

Adobe Campaign Classic is susceptible to an improper control of code generation vulnerability, enabling potential arbitrary code execution in the context of the current user. Attackers can exploit this issue without the need for user interaction, essentially allowing them to run arbitrary code which could compromise the integrity and security of affected systems. The scope of the vulnerability has been assessed, indicating the need for immediate attention to safeguard against potential exploitation.

Affected Version(s)

Adobe Campaign Classic 0 <= 7.4.4 build 9401

Adobe Campaign Classic 7.4.4 build 9402

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.