CRITICAL🇵🇱 Wersja polska

CVE-2026-48381

CVSS 9.0v3.1pub. 2026-08-11upd. 2026-08-28

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Adobe Campaign

    APP
    Adobe
    7.2.1 – 7.4.4 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCESQLi
CWE
References

Related vulnerabilities

CVE-2026-76197CRITICAL10.0same product

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Comma...

CVE-2026-76195CRITICAL10.0same product

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Comma...

CVE-2026-76193CRITICAL10.0same product

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could resu...

CVE-2026-71398CRITICAL10.0same product

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbi...

CVE-2026-27302CRITICAL10.0same product

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbi...