Unauthenticated SQL Injection in Adobe Campaign Classic Leads to Remote Code Execution (CVE-2026-48330)
Overview
Adobe Campaign Classic (ACC) suffers from a critical SQL injection vulnerability (CVE-2026-48330) with a CVSS score of 10.0. Attackers can exploit this flaw to execute arbitrary SQL commands and achieve remote code execution without authentication or user interaction, posing an immediate risk to enterprise systems.
Technical Analysis
The vulnerability stems from improper input sanitization in ACC's HTTP endpoints, allowing attackers to inject malicious SQL payloads via query parameters or tracking URLs. Exploitation methods include stacked SQL queries or leveraging xp_cmdshell/UDF execution paths to escalate privileges. The changed scope enables lateral movement from the database to the host system, bypassing traditional security boundaries.
Enterprise & DIB Impact
Defense Industrial Base (DIB) and enterprise environments using ACC are at severe risk of data exfiltration, system compromise, and operational disruption. The lack of user interaction requirements and unauthenticated access significantly lowers the barrier for exploitation, particularly for automated attack campaigns.
Recommended Actions
- Apply Adobe's official security patch immediately
- enforce strict input validation for all database queries
- monitor logs for anomalous SQL patterns
- update intrusion detection systems with relevant signatures
- and conduct third-party code audits for similar vulnerabilities.
Need Help Assessing Your Exposure?
Axiom Cyber Research provides vulnerability assessment, red team operations, and security advisory services to the Defense Industrial Base and regulated sectors.
Schedule a ConsultationFull security advisory on 247alerts.net →