CVE-2026-48330Disclosure(adobe / campaign)

MEDIUMCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch adobe campaign systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary SQL commands, potentially gaining elevated access or control over the application. Exploitation of this issue does not require user interaction. Scope is changed.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • campaign
  • linux_kernel
  • windows

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 2 mentions (2026-08-04); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Products
campaignlinux_kernelwindows

2 versions affected across 3 products

Deep dive

Activity timeline8 mentions / 5d
01122Mentions · 2026-08-03: 1Mentions · 2026-08-04: 2Mentions · 2026-08-05: 2Mentions · 2026-08-06: 2Mentions · 2026-08-14: 1PoC Mentioned / Linked · 2026-08-04: 1Exploit Tool / Code · 2026-08-04: 1Patch / Workaround · 2026-08-05: 1Patch / Workaround · 2026-08-06: 1Technical Details · 2026-08-03: 1Technical Details · 2026-08-04: 1Technical Details · 2026-08-05: 2Technical Details · 2026-08-06: 2Technical Details · 2026-08-14: 108-0308-0408-0508-0608-14
Signal classification4 categories
Disclosure
450.0%
Patch
225.0%
Exploit
112.5%
General
112.5%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-08-031
Disclosure1
2026-08-042
Exploit1General1
2026-08-052
Disclosure1Patch1
2026-08-062
Disclosure1Patch1
2026-08-141
Disclosure1
Full discourse8 posts
  • Jamie Parfet@JamieParfet
    Disclosure

    Another day, another Adobe security bulletin 🔥 All unauthenticated, exploitable on a stock install: CVE-2026-48323 (RCE) CVE-2026-48331 (SSRF) CVE-2026-48330 (SQLi) CVE-2026-48326 (SQLi) CVE-2026-48333 (Auth bypass > RCE) https://helpx.adobe.com/security/products/campaign/apsb26-120.html

    Post summary

    Adobe issued a security bulletin announcing several unauthenticated CVEs that can be exploited on stock installations, with types enumerated but no active exploits or patches mentioned.

    00020212
    389 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🧨 Adobe Campaign Classic Hit With Multiple CVSS 10.0 Flaws Adobe Campaign Classic (ACC) accounts for three critical vulnerabilities this week, and none of them have patches. CVE-2026-48330 is a SQL injection flaw, CVE-2026-48323 involves…

    Post summary

    Adobe Campaign Classic has three critical CVE‑2026‑48xxx flaws with CVSS 10.0, including a SQL injection (CVE‑2026‑48330), and currently no patches or exploits are reported.

    1000036
    88 followersView on X
  • kawn@kawn2020
    Patch

    #securityupdate #adobeupdate #adobe #CampaignClassic Adobe から,Campaign Classic で更新をリリース. 適用優先度「1」,緊急度には「Critical」 7 件(うち CVSS 10.0 3 件)が含まれる. ・CVE-2026-48323 ・CVE-2026-48330 ・CVE-2026-48331 https://x.com/kawn2020/status/2084857607664419093

    Post summary

    Adobe issued a critical patch for three CVEs in Campaign Classic, addressing high‑severity vulnerabilities confirmed with CVSS scores.

    1000087
    92 followersView on X
  • ExploitGrid@exploitgrid
    Exploit

    [CVE] CVE-2026-48330 [HIGH PRIORITY] #Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements us... 🔗 https://exploitgrid.net/cve/CVE-2026-48330

    Post summary

    A high‑priority CVE-2026-48330 for Adobe Campaign Classic is linked to a potential exploit on exploitgrid, but no evidence of active wild attacks or mitigation actions is provided.

    1000030
    29 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️# ExploitGrid Daily #Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-33591 CVE-2026-48323 CVE-2026-48330 CVE-2026-48331 CVE-2026-48326 ..🧵👇

    Post summary

    The content merely enumerates CVE identifiers without any supporting details, links, or context.

    1000039
    29 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-48330 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in… https://www.cve.org/CVERecord?id=CVE-2026-48330

    Post summary

    The text announces CVE-2026-48330, describing it as an SQL injection flaw in Adobe Campaign Classic that could lead to critical impact.

    01000783
    57.9K followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    📧 Adobe Campaign Classic hit by CVE-2026-48330 — a critical CVSS 10 SQL injection enabling arbitrary code execution. No auth, no user interaction, full scope impact. Patch via APSB26-120 now. #cybersecurity #ciso #cto #vulnerabilities #msp #mssp https://secalerts.co/vulnerability/CVE-2026-48330?utm_campaign=x https://t.co/3I1P7xqU39

    Post summary

    Adobe Campaign Classic is affected by CVE‑2026‑48330, a critical SQL injection that allows arbitrary code execution, and a patch (APSB26-120) is now available.

    00000213
    876 followersView on X
  • kawn@kawn2020
    Disclosure

    #securityupdate #adobeupdate #adobe #CampaignClassic Adobe Campaign Classic ACC v7 7.4.3 build 9399 ・CVE-2026-48323(CVSS 10.0) ・CVE-2026-48330(〃 10.0) ・CVE-2026-48331(〃 10.0) ・CVE-2026-48317 ・CVE-2026-48326(〃 9.9) ・CVE-2026-48333(〃 9.8) ・CVE-2026-48399

    Post summary

    The tweet announces several high‑severity CVEs (CVE‑2026‑48323, ‑48330, ‑48331, etc.) affecting Adobe Campaign Classic, including CVSS scores, without providing PoCs, exploit code, or patch information.

    0000068
    92 followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
Appadobecampaign---
Appadobecampaign7.4.3--
Appadobecampaign7.4.3--
Appadobecampaign7.4.3--
Appadobecampaign7.4.3--
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more