Adobe Campaign Classic contains an unauthenticated OS command injection flaw that allows arbitrary code execution over the network with no user interaction, rated CVSS 10.0.
What Is It
CVE-2026-82004 is an Improper Neutralization of Special Elements used in an OS Command vulnerability (CWE-78) affecting Adobe Campaign Classic (ACC). Special characters passed into an OS command are not properly neutralized, allowing an attacker to execute arbitrary code in the context of the current user. Adobe's PSIRT published the advisory on 2026-09-08; the NVD record remains in "Undergoing Analysis" status.
Why It Matters
The vulnerability carries a CVSS 3.1 base score of 10.0 (CRITICAL) with vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. Every exploitability factor is worst-case: the attack is remotely reachable over the network, requires low attack complexity, needs no privileges, and requires no user interaction. The UI:N component of the vector published in Adobe's advisory is the basis for the no-user-interaction assessment.
The scope is marked as changed, meaning successful exploitation impacts resources beyond the vulnerable component's security authority; a compromise is not contained to the ACC process itself. Confidentiality, integrity, and availability impacts are all rated High, giving the maximum exploitability subscore of 3.9 and an impact subscore of 6.0.
Adobe Campaign Classic is a marketing campaign management platform that typically holds large volumes of customer contact data, making arbitrary code execution on these hosts a high-value outcome for an attacker.
What's Vulnerable
Per Adobe's affected-product data:
- Adobe Campaign Classic: all versions up to and including 7.4.4 build 9401 are affected.
- 7.4.4 build 9402 and later are unaffected.
No CPE match data has been published in the NVD record yet.
Patch Status
Adobe has released a fixed build. Upgrading Adobe Campaign Classic to 7.4.4 build 9402 or later remediates the issue. Refer to Adobe Security Bulletin APSB26-142 for full upgrade guidance.
CVE-2026-82004 does not appear in the CISA Known Exploited Vulnerabilities catalog at this time; there is no confirmed evidence of active exploitation in the wild, and therefore no federally mandated remediation deadline. Given the 10.0 score and the absence of any authentication or interaction requirement, this should still be treated as an urgent patch regardless of KEV status.