Description
ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-07-14
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an improper control of code generation that allows attackers to inject and execute arbitrary code on the ColdFusion server. The CVE description explicitly states that the injected code runs in the context of the current user and that exploitation does not require user interaction. The advisory notes that the scope is changed, but it does not provide details on the resulting privilege level; it is inferred that a scope change could enable an attacker to gain higher privileges, but this inference is not directly stated in the input.

Affected Systems

Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are the impacted products. No specific patched versions are listed in the CNA data, so any installation of these releases should be reviewed for the vulnerability.

Risk and Exploitability

With a CVSS score of 9.6 the vulnerability is rated as critical, and the EPSS score of less than 1% indicates that exploitation attempts are currently rare. The flaw is not listed in CISA’s KEV catalog. Attackers can exploit the issue remotely by sending specially crafted content to the ColdFusion instance, triggering code execution without user interaction. The noted scope change suggests the possibility of privilege escalation, but this is an inferred consequence rather than a directly stated fact.

Generated by OpenCVE AI on August 1, 2026 at 09:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch or update for ColdFusion 2023/2025 as detailed in Adobe’s security advisory.
  • Restrict network access to the ColdFusion server and disable or lock down features that allow dynamic code evaluation as a temporary protection.
  • Continuously monitor application logs and alert on unexpected execution patterns to detect exploitation attempts early.

Generated by OpenCVE AI on August 1, 2026 at 09:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025
Vendors & Products Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Title ColdFusion | Improper Control of Generation of Code ('Code Injection') (CWE-94)
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Adobe Coldfusion 2023 Coldfusion 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T10:34:24.993Z

Reserved: 2026-05-21T15:28:38.137Z

Link: CVE-2026-48322

cve-icon Vulnrichment

Updated: 2026-07-15T10:34:18.388Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:15:03Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')