Description
ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-07-14
Score: 7.7 High
EPSS: 10.7% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

ColdFusion is vulnerable to a Server-Side Request Forgery that allows a low-privileged attacker to bypass security mechanisms and read data that should be protected. The flaw can be triggered without user interaction and changes the security scope of the application, potentially exposing internal resources to the attacker.

Affected Systems

Adobe ColdFusion versions 2023 and 2025 are affected. No specific patch versions are listed, so any release prior to the official fix should be considered vulnerable.

Risk and Exploitability

The CVSS score of 7.7 reflects a moderate to high severity, while an EPSS score of 11% indicates a relatively low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, but it can be leveraged directly from the exposed service, suggesting that the attack vector is remote exploitation of the ColdFusion instance.

Generated by OpenCVE AI on August 3, 2026 at 03:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe ColdFusion patch for the affected release series as released by Adobe.
  • Limit or disable ColdFusion’s outgoing HTTP request functionality if it is not required for business operations.
  • Implement network segmentation and firewall rules to restrict outbound traffic initiated by ColdFusion to only those destinations that are explicitly permitted.
  • Configure ColdFusion’s security settings to enforce strict input validation on any externally supplied URLs and enable the built-in SSRF protections where available.
  • Monitor ColdFusion logs for abnormal outbound connections and investigate any unexpected traffic promptly.

Generated by OpenCVE AI on August 3, 2026 at 03:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025
Vendors & Products Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025

Wed, 15 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.
Title ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918)
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Adobe Coldfusion 2023 Coldfusion 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T17:38:35.635Z

Reserved: 2026-05-21T15:28:38.139Z

Link: CVE-2026-48332

cve-icon Vulnrichment

Updated: 2026-07-15T17:38:31.860Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T03:15:05Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)