Adobe has disclosed a critical SQL injection flaw in Adobe Campaign Classic that lets a low-privileged, remote attacker bypass security controls and gain unauthorized read and limited write access.
Identifier caveat: this brief was circulated under the identifier "CVE-2026-82011." That ID falls outside the range of CVE identifiers assigned so far in 2026, which are currently in the five-digit CVE-2026-1xxxx band. Treat the identifier as unverified: it is likely a transcription error or a fabricated reference. Track this issue by vendor bulletin (APSB26-142) until the correct CVE ID is confirmed against NVD or the CVE Program, and do not use the unverified ID to key ticketing, scanner suppressions, or exception records.
What Is It
The reported flaw is an improper neutralization of special elements used in an SQL command (CWE-89) affecting Adobe Campaign Classic (ACC). Per Adobe's advisory, the flaw results in a security feature bypass: an attacker with low privileges can leverage it to bypass security measures and gain unauthorized read and limited write access. Exploitation requires no user interaction.
The CVSS 3.1 base score is 9.1 (CRITICAL), with vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L. The record is attributed to Adobe PSIRT with a publication date of 2026-09-22 and a status of "Awaiting Analysis" at NVD, both of which should be re-confirmed once a valid identifier is established.
Why It Matters
Three things push this into critical territory despite requiring some level of access:
- Network-reachable, low complexity, no user interaction. An attacker needs only low privileges; no admin role, no tricking a user into clicking anything.
- Scope is changed. The vulnerability lets the attacker affect resources beyond the vulnerable component's own security authority, which is what drives the score to 9.1 rather than a mid-range number.
- High confidentiality impact. Campaign Classic is a marketing automation platform; the databases behind it typically hold large volumes of customer contact and campaign data. Unauthorized read access at scale is the core risk here.
Integrity and availability impacts are rated Low; this is primarily a data exposure and security-bypass issue, not a destructive one.
What's Vulnerable
Adobe Campaign Classic (ACC):
- Affected: all versions up to and including 7.4.4 build 9401
- Unaffected: 7.4.4 build 9402 and later
No CPE entries have been published in the NVD record yet. Because the build boundary comes from the vendor bulletin rather than an analyzed CVE record, confirm it against APSB26-142 before scoping an upgrade campaign.
Patch Status
Adobe has shipped a fix. Upgrade Adobe Campaign Classic to 7.4.4 build 9402 or later; that build is explicitly listed as unaffected. Refer to Adobe security bulletin APSB26-142 for vendor upgrade guidance; with the CVE ID in question, the bulletin is the authoritative reference for remediation.
On exploitation status, the sources available at the time of writing are limited: Adobe's bulletin does not state that the issue has been exploited in the wild, and no exploitation references are available. That is an absence of public reporting, not a confirmed absence of exploitation. Because the CISA Known Exploited Vulnerabilities catalog is updated continuously, defenders who need to know whether a KEV entry and its associated remediation deadline apply should check the catalog directly, searching on the product rather than the unverified identifier, rather than rely on a point-in-time summary.
Sources
- NVD, CVE-2026-82011 (identifier unverified; expect no record to resolve at this URL)
- Adobe Security Bulletin APSB26-142; Adobe Campaign Classic
- CISA Known Exploited Vulnerabilities Catalog