CVE-2026-48326: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary cod
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-48326
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-48326 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for Adobe Campaign Classic
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-48399: Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerabil…nvd · 2026-08-03
- criticalCVE-2026-48333: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that coul…nvd · 2026-08-03
- criticalCVE-2026-48331: Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability…nvd · 2026-08-03
- criticalCVE-2026-48330: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements use…nvd · 2026-08-03
- criticalCVE-2026-48323: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Use…nvd · 2026-08-03
- criticalCVE-2026-48317: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynami…nvd · 2026-08-03
More from NVD Recent CVEs
- mediumCVE-2026-8508: An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S…2026-08-04
- highCVE-2026-6837: A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel …2026-08-04
- mediumCVE-2026-18720: A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown co…2026-08-04
- mediumCVE-2026-17614: A path traversal flaw was found in WildFly's domain mode implementation. The LocalFileReposito…2026-08-04
- mediumCVE-2026-18719: A vulnerability was detected in cemtan sar2html 4.0.0. This affects an unknown part of the fil…2026-08-04