CVE-2026-48317: Adobe Campaign Classic (ACC) | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95)
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48317?
The severity of CVE-2026-48317 is critical, with a CVSS score of 9.6.
How do I fix CVE-2026-48317?
To fix CVE-2026-48317, ensure you apply the latest security updates provided by Adobe for Adobe Campaign Classic.
What is the impact of CVE-2026-48317?
CVE-2026-48317 may allow an attacker to execute arbitrary code in the context of the current user.
What type of vulnerability is CVE-2026-48317?
CVE-2026-48317 is classified as an Improper Neutralization of Directives in Dynamically Evaluated Code, also known as eval injection.
Who is affected by CVE-2026-48317?
CVE-2026-48317 affects users of Adobe Campaign Classic (ACC) that have not updated to the latest security patch.