criticalOther

Adobe Campaign Classic OS Command Injection (CVE-2026-82004)

First seen Sep 11, 2026 · Updated Sep 11, 2026 · CVSS 10

adobeos-command-injectionrceunauthenticatedcvss10campaign-classicmarketing-platform

A critical OS Command Injection vulnerability in Adobe Campaign Classic (ACC) allows arbitrary code execution in the context of the current user without any user interaction, and has a maximum CVSS score of 10.0 with a changed scope. This flaw poses severe risk to organizations running ACC for marketing automation, as unauthenticated or minimally-privileged attackers could gain full control of affected servers.

Technical Analysis

CVE-2026-82004 stems from improper neutralization of special elements used in OS commands within Adobe Campaign Classic, enabling attackers to inject and execute arbitrary OS-level commands. The vulnerability does not require user interaction, and the 'Scope Changed' designation indicates that successful exploitation can impact resources beyond the vulnerable component itself, likely allowing lateral movement or broader system compromise. Given the CVSS 10.0 rating, this is likely remotely exploitable with low attack complexity and no privileges required, making it highly attractive for mass exploitation and automated scanning campaigns. Organizations should treat this as an imminent threat given ACC's common integration with customer data platforms and marketing databases containing sensitive PII. If AI agent systems or LLM-based automation tools are integrated with or run on the same infrastructure as Adobe Campaign Classic (e.g., agents that pull customer engagement data via ACC APIs, or orchestration hosts co-located with ACC instances), compromise of the underlying host could expose API keys, credentials, or data pipelines that agents rely on, enabling broader downstream compromise of agentic workflows.

Affected Systems

Adobe Campaign Classic (ACC) - specific version ranges pending official Adobe security bulletin confirmation; typically affects on-premise and hybrid ACC deployments across Windows and Linux server environments.

Indicators of Compromise

  • No specific IOCs published at this time; monitor Adobe Security Bulletin (APSB) advisories and NVD for updates.

Remediation Steps

  1. 1

    Apply Adobe Security Patch

    Monitor Adobe's official security bulletin for CVE-2026-82004 and apply the vendor-released patch immediately upon availability.

  2. 2

    Restrict Network Access

    Limit exposure of Adobe Campaign Classic management interfaces to trusted internal networks and enforce firewall rules to block unnecessary external access.

  3. 3

    Input Validation and WAF Rules

    Deploy web application firewall rules to detect and block anomalous OS command injection patterns targeting ACC endpoints as a temporary mitigation.

  4. 4

    Audit and Rotate Credentials

    Audit service accounts and API keys used by ACC and any connected systems (including AI agent or automation pipelines), and rotate credentials if compromise is suspected.

  5. 5

    Enable Logging and Monitoring

    Increase logging verbosity on ACC servers and monitor for unusual process execution, outbound connections, or privilege escalation attempts.

CVE / Advisory IDs

CVE-2026-82004

Industries Most Exposed

marketingretaile-commercefinancial servicesmediatechnology

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.