AdobeCVE-2026-48448
Adobe Campaign Classic: SQL injection
High8.6CVE-2026-48448 · Published Jul 30, 2026 · updated Aug 28, 2026
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to gain file system read access. Exploitation of this issue does not require user interaction. Scope is changed.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Adobe Campaign Classic Product | <= 7.4.3 build 9397 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-89
More Adobe advisories
All Adobe| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 31 | Adobe Premiere: out-of-bounds write | High7.8 | No fix yet |
| Jul 30 | Adobe Campaign Classic: improper authorization | Critical10.0 | No fix yet |
| Jul 28 | Adobe Bridge: improper authorization | High8.2 | No fix yet |
| Jul 28 | Adobe Bridge: untrusted search path | High8.2 | No fix yet |
| Jul 28 | Adobe Bridge: out-of-bounds write | High7.8 | No fix yet |
| Jul 28 | Adobe Bridge: out-of-bounds write | High7.8 | No fix yet |