← Back to Research Blog
CRITICAL CVE-2026-48330

Unauthenticated SQL Injection in Adobe Campaign Classic Leads to Remote Code Execution (CVE-2026-48330)

10.0
CRITICAL
adobe campaign classic
2026-08-16

Overview

Adobe Campaign Classic (ACC) suffers from a critical SQL injection vulnerability (CVE-2026-48330) with a CVSS score of 10.0. Attackers can exploit this flaw to execute arbitrary SQL commands and achieve remote code execution without authentication or user interaction, posing an immediate risk to enterprise systems.


Technical Analysis

The vulnerability stems from improper input sanitization in ACC's HTTP endpoints, allowing attackers to inject malicious SQL payloads via query parameters or tracking URLs. Exploitation methods include stacked SQL queries or leveraging xp_cmdshell/UDF execution paths to escalate privileges. The changed scope enables lateral movement from the database to the host system, bypassing traditional security boundaries.

Enterprise & DIB Impact

Defense Industrial Base (DIB) and enterprise environments using ACC are at severe risk of data exfiltration, system compromise, and operational disruption. The lack of user interaction requirements and unauthenticated access significantly lowers the barrier for exploitation, particularly for automated attack campaigns.

Recommended Actions

Need Help Assessing Your Exposure?

Axiom Cyber Research provides vulnerability assessment, red team operations, and security advisory services to the Defense Industrial Base and regulated sectors.

Schedule a Consultation
Full security advisory on 247alerts.net →
Axiom Cyber Research
Axiom Cyber Research, LLC is a Service-Disabled Veteran-Owned Small Business (SDVOSB) providing elite cybersecurity consulting to the Defense Industrial Base and regulated sectors. Founded by a 20+ year veteran with deep offensive and defensive cyber expertise. Our CVE intelligence program actively tracks emerging vulnerabilities to help organizations prioritize remediation and reduce exposure windows.
Baltimore, MD  ·  axiomcyber.io  ·  247alerts.net  ·  SDVOSB  ·  NAICS 541512