CVE-2026-48448

HIGH

Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)

Title source: cna
STIX 2.1

Description

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to gain file system read access. Exploitation of this issue does not require user interaction. Scope is changed.

References (1)

Core 1
Core References

Scores

CVSS v3 8.6
EPSS 0.0037
EPSS Percentile 29.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (2)
Adobe/Adobe Campaign Classic < 7.4.3 build 9397
Adobe/Adobe Campaign Classic 7.4.3 build 9398
Published Jul 30, 2026
Tracked Since Jul 30, 2026