VYPR
High severity8.6NVD Advisory· Published Jul 30, 2026· Updated Aug 28, 2026

CVE-2026-48448

CVE-2026-48448

Description

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to gain file system read access. Exploitation of this issue does not require user interaction. Scope is changed.

Affected products

6
  • cpe:2.3:a:adobe:campaign:*:*:*:*:classic:*:*:*+ 4 more
    • cpe:2.3:a:adobe:campaign:*:*:*:*:classic:*:*:*range: <=7.4.2
    • cpe:2.3:a:adobe:campaign:7.4.3:9394:*:*:classic:*:*:*
    • cpe:2.3:a:adobe:campaign:7.4.3:9396:*:*:classic:*:*:*
    • cpe:2.3:a:adobe:campaign:7.4.3:9397:*:*:classic:*:*:*
    • cpe:2.3:a:adobe:campaign:7.4.3:9398:*:*:classic:*:*:*

Patches

Vulnerability mechanics

References

1

News mentions

1