CVE-2026-82011: Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access. Exploitation of this issue does not require user interaction. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
An attacker needs low-privileged access to Adobe Campaign Classic. Exploitation does not require user interaction and can be performed remotely, as indicated by the network attack vector.
What could a successful attacker do?
Successful exploitation could bypass security measures, allowing unauthorized read access and limited write access. The vulnerability has changed scope, meaning its impact can extend beyond the authority of the initially compromised low-privileged account.