High priorityDisclosed

Advisory · CVE-2026-82003

Input validation flaw in Adobe Campaign Classic can lead to code execution

An improper input validation flaw in Adobe Campaign Classic lets a low-privileged attacker execute arbitrary code, though exploitation depends on conditions beyond the attacker's control. CVSS 8.5.

Vendor
Adobe
Product
Adobe Campaign Classic
Identifier / CWE
CVE-2026-82003
CWE-20
Action timing
Immediate
ELI5

Explain it like I’m five

A combination lock accepts your code but only sometimes checks every digit. An attacker who knows when it gets lazy can slip through with a wrong code.

SIMPLIFIED_ATTACK_PATH04 STEPS
  1. 01Low-privileged access

    An attacker holds a low-privileged account on Adobe Campaign Classic.

  2. 02Crafted input

    They submit input the application validates incompletely.

  3. 03Conditions align

    Exploitation additionally depends on conditions beyond the attacker's full control.

  4. 04Code execution

    When those conditions hold, arbitrary code runs in the context of the current user.

What happened

Adobe security bulletin APSB26-142 includes CVE-2026-82003, an improper input validation vulnerability (CWE-20) in Adobe Campaign Classic. A low-privileged attacker can exploit it without user interaction to execute arbitrary code, although the NVD entry notes exploitation depends on conditions beyond the attacker’s control. Adobe Campaign Classic builds up to and including 7.4.4 build 9401; fixed in 7.4.4 build 9402. NVD rates it CVSS 8.5 (v3.1).

What to do

  1. Upgrade Adobe Campaign Classic to 7.4.4 build 9402 or later.
  2. Include Campaign servers in the same log review as the higher-severity items in this bulletin.

Management note

Conditional exploitability lowers urgency but not the patching decision; the fix rides along with the rest of APSB26-142 at zero marginal cost.