CVE-2026-82004
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- CWE
- CWE-78
- Published
- 2026-09-08
- Last modified
- 2026-09-08
Affected products
- Adobe Adobe Campaign Classic
- Adobe Adobe Campaign Classic
Weakness type
Related vulnerabilities
- CVE-2026-79641 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-87088 — Tanium addressed an unauthorized code execution vulnerability in Enforce.
- CVE-2026-78630 — Improper Input Neutralization in Okta Access Gateway SNMP Configuration Processing
- CVE-2026-81349 — Azure HDInsight Ambari Elevation of Privilege Vulnerability
- CVE-2026-86733 — Snipe-IT before 8.7.0 Remote Code Execution via Backup Restore
- CVE-2026-61517 — Netis NX10 OS Command Injection via Ping Diagnostic Handler
- CVE-2026-71376 — OS Command Injection Vulnerability in Cosminexus Component Container
- CVE-2026-76561 — Pki-core: dogtag/pki: certprofile-import allows code execution via unsanitized profile content (externalprocessconstraint)