Advisory · CVE-2026-82003
Input validation flaw in Adobe Campaign Classic can lead to code execution
An improper input validation flaw in Adobe Campaign Classic lets a low-privileged attacker execute arbitrary code, though exploitation depends on conditions beyond the attacker's control. CVSS 8.5.
- Vendor
- Adobe
- Product
- Adobe Campaign Classic
- Identifier / CWE
- CVE-2026-82003
CWE-20 - Action timing
- Immediate
Explain it like I’m five
A combination lock accepts your code but only sometimes checks every digit. An attacker who knows when it gets lazy can slip through with a wrong code.
- 01Low-privileged access
An attacker holds a low-privileged account on Adobe Campaign Classic.
- 02Crafted input
They submit input the application validates incompletely.
- 03Conditions align
Exploitation additionally depends on conditions beyond the attacker's full control.
- 04Code execution
When those conditions hold, arbitrary code runs in the context of the current user.
What happened
Adobe security bulletin APSB26-142 includes CVE-2026-82003, an improper input validation vulnerability (CWE-20) in Adobe Campaign Classic. A low-privileged attacker can exploit it without user interaction to execute arbitrary code, although the NVD entry notes exploitation depends on conditions beyond the attacker’s control. Adobe Campaign Classic builds up to and including 7.4.4 build 9401; fixed in 7.4.4 build 9402. NVD rates it CVSS 8.5 (v3.1).
What to do
- Upgrade Adobe Campaign Classic to 7.4.4 build 9402 or later.
- Include Campaign servers in the same log review as the higher-severity items in this bulletin.
Management note
Conditional exploitability lowers urgency but not the patching decision; the fix rides along with the rest of APSB26-142 at zero marginal cost.