Description
ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-07-14
Score: 9.1 Critical
EPSS: 1.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

ColdFusion contains a CWE-89 vulnerability, Improper Neutralization of Special Elements used in an SQL Command, that permits an attacker to inject malicious SQL statements. The injection flaw can result in arbitrary code execution in the context of the current user. Because the vulnerability changes the system scope, it may allow an attacker with high privileges to execute code with higher privileges on the underlying system.

Affected Systems

Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are affected; all releases within those major versions should be considered vulnerable until the advisory specifies otherwise.

Risk and Exploitability

The CVSS score of 9.1 classifies this vulnerability as high severity. The EPSS score of 1% indicates a low probability of exploitation at this time, yet the flaw remains a significant risk. It is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is automated web requests that include untrusted input, and the attack does not require user interaction. Because the vulnerability changes scope, executing arbitrary code can affect the application or the underlying system.

Generated by OpenCVE AI on August 1, 2026 at 09:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Adobe ColdFusion patch that addresses the SQL injection, as specified in the official advisory.
  • Restart the ColdFusion services to finalize the patch application.
  • Enhance input validation and use parameterized queries for all database interactions; deploy a web application firewall to block suspicious SQL injection traffic.

Generated by OpenCVE AI on August 1, 2026 at 09:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025
Vendors & Products Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025

Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Title ColdFusion | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Coldfusion 2023 Coldfusion 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-21T21:20:48.788Z

Reserved: 2026-05-21T15:28:38.137Z

Link: CVE-2026-48324

cve-icon Vulnrichment

Updated: 2026-07-15T10:33:24.493Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:15:03Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')