CVE-2026-48448

High8.6Published on July 30, 2026

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to gain file system read access. Exploitation of this issue does not require user interaction. Scope is changed.

CVSS score8.6 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Weakness type (CWE)CWE-89
Vendorslinux, microsoft, adobe

Affected products

VendorsProductVersions
adobecampaign<= 7.4.2
linuxlinux kernel-
microsoftwindows-

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database