Description
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-07-06
Score: 10 Critical
EPSS: 1.6% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper input validation flaw that permits arbitrary code execution in the context of the current user. Attackers can trigger it without any user interaction, and the system compromise. The weakness is insufficient input checks.

Affected Systems

Adobe ColdFusion versions 2025.9, 2023.20 and all earlier releases are affected. Any server running these releases is vulnerable until a fix is applied or the application removed.

Risk and Exploitability

The CVSS score of 10 indicates an extremely severe vulnerability. The EPSS score of 2% indicates a low but non-negligible likelihood of exploitation. The vulnerability is not listed in CISA KEV, yet the lack of such a listing does not mitigate the risk. Based on the description, the flaw can be triggered by sending crafted input without any user interaction, making it a highly dangerous threat.

Generated by OpenCVE AI on July 26, 2026 at 20:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe ColdFusion patch or upgrade to a supported release as detailed in Adobe Security Bulletin APSB26. An upgrade cannot be performed immediately to essential services and placing it behind a firewall to limit exposure.
  • Deploy a web application firewall or implement application-level input-validation rules to filter suspicious requests as a temporary countermeasure.
  • Restrict network exposure by placing the inbound trusted IP ranges.

Generated by OpenCVE AI on July 26, 2026 at 20:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe coldfusion
Vendors & Products Adobe
Adobe coldfusion

Mon, 06 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Description ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Title ColdFusion | Improper Input Validation (CWE-20)
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Adobe Coldfusion
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-07T13:10:00.267Z

Reserved: 2026-05-21T15:28:38.137Z

Link: CVE-2026-48316

cve-icon Vulnrichment

Updated: 2026-07-06T18:56:45.859Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T20:30:03Z

Weaknesses
  • CWE-20

    Improper Input Validation