Cyber & AI intelligence
Wasteland.
Briefs indexed2842
Issues29
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-82011 2026-09-22

Adobe Campaign Classic — Critical SQL Injection (Identifier Unverified)

"Adobe has disclosed a critical SQL injection flaw in Adobe Campaign Classic that lets a low-privileged, remote attacker bypass security controls and gain unauthorized read and limited write access."

Adobe has disclosed a critical SQL injection flaw in Adobe Campaign Classic that lets a low-privileged, remote attacker bypass security controls and gain unauthorized read and limited write access.

Identifier caveat: this brief was circulated under the identifier "CVE-2026-82011." That ID falls outside the range of CVE identifiers assigned so far in 2026, which are currently in the five-digit CVE-2026-1xxxx band. Treat the identifier as unverified: it is likely a transcription error or a fabricated reference. Track this issue by vendor bulletin (APSB26-142) until the correct CVE ID is confirmed against NVD or the CVE Program, and do not use the unverified ID to key ticketing, scanner suppressions, or exception records.

What Is It

The reported flaw is an improper neutralization of special elements used in an SQL command (CWE-89) affecting Adobe Campaign Classic (ACC). Per Adobe's advisory, the flaw results in a security feature bypass: an attacker with low privileges can leverage it to bypass security measures and gain unauthorized read and limited write access. Exploitation requires no user interaction.

The CVSS 3.1 base score is 9.1 (CRITICAL), with vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L. The record is attributed to Adobe PSIRT with a publication date of 2026-09-22 and a status of "Awaiting Analysis" at NVD, both of which should be re-confirmed once a valid identifier is established.

Why It Matters

Three things push this into critical territory despite requiring some level of access:

Integrity and availability impacts are rated Low; this is primarily a data exposure and security-bypass issue, not a destructive one.

What's Vulnerable

Adobe Campaign Classic (ACC):

No CPE entries have been published in the NVD record yet. Because the build boundary comes from the vendor bulletin rather than an analyzed CVE record, confirm it against APSB26-142 before scoping an upgrade campaign.

Patch Status

Adobe has shipped a fix. Upgrade Adobe Campaign Classic to 7.4.4 build 9402 or later; that build is explicitly listed as unaffected. Refer to Adobe security bulletin APSB26-142 for vendor upgrade guidance; with the CVE ID in question, the bulletin is the authoritative reference for remediation.

On exploitation status, the sources available at the time of writing are limited: Adobe's bulletin does not state that the issue has been exploited in the wild, and no exploitation references are available. That is an absence of public reporting, not a confirmed absence of exploitation. Because the CISA Known Exploited Vulnerabilities catalog is updated continuously, defenders who need to know whether a KEV entry and its associated remediation deadline apply should check the catalog directly, searching on the product rather than the unverified identifier, rather than rely on a point-in-time summary.

Sources