Description
ColdFusion is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-07-14
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

ColdFusion is vulnerable to an improper input validation flaw that permits a low‑privileged attacker to bypass a core security feature, enabling unauthorized read access to protected resources. The flaw alters the application scope and does not require user interaction, making it potentially exploitable from any environment with network connectivity to the affected server. The weakness is classified as CWE‑20.

Affected Systems

All installations of Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are vulnerable, as the vendor lists the two product lines without specifying version ranges. Until Adobe releases a patch or a newer version that incorporates the fix, every installation in these lines is considered vulnerable.

Risk and Exploitability

The CVSS score of 7.7 marks the issue as high severity, yet the EPSS score of less than 1% indicates a very low probability of real‑world exploitation. The vulnerability is not present in CISA’s KEV catalog. The lack of a user‑interaction requirement and the description’s implication of remote reachability suggest that the attack vector is likely network‑based access to the ColdFusion service, which can be exploited by attackers with external network exposure.

Generated by OpenCVE AI on July 31, 2026 at 04:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe ColdFusion update that addresses the input validation flaw or upgrade to a version that contains the fix.
  • Disable or tightly configure the ColdFusion security feature that is being bypassed, ensuring that only authenticated and authorized users can access sensitive data.
  • Implement server‑side input validation for all externally supplied data, rejecting any input that does not conform to expected formats or types.

Generated by OpenCVE AI on July 31, 2026 at 04:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025
Vendors & Products Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025

Tue, 14 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description ColdFusion is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.
Title ColdFusion | Improper Input Validation (CWE-20)
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Adobe Coldfusion 2023 Coldfusion 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T15:12:02.100Z

Reserved: 2026-05-21T15:28:38.138Z

Link: CVE-2026-48328

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T04:45:17Z

Weaknesses
  • CWE-20

    Improper Input Validation