Description
ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.
Published: 2026-08-11
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A heap‑based buffer overflow exists in Adobe ColdFusion. The flaw can allow execution of arbitrary code in the context of the user that owns the ColdFusion service. The vulnerability is identified as CWE‑122. An attacker may cause the application to write outside the bounds of a heap object, potentially leading to code execution. The exploit does not need user interaction; however, the actual exploitation requires conditions that lie beyond the attacker’s direct control, so it is not trivially triggerable.

Affected Systems

The affected products are Adobe ColdFusion 2023 and Adobe ColdFusion 2025, with no specific version ranges provided. All installations of these products are vulnerable until a vendor patch is applied.

Risk and Exploitability

The CVSS score of 8.1 classifies this flaw as High severity, indicating that exploitation could lead to complete compromise of the affected system. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, which suggests a lower documented exploitation rate, though the lack of EPSS data prevents a precise estimation of exploit probability. The flaw can be triggered without user interaction; the likely attack vector therefore involves remote exploitation of a ColdFusion service that is reachable over the network. If the conditions to trigger the overflow are satisfied, the attacker could gain local execution rights, effectively escalating privileges within the ColdFusion environment.

Generated by OpenCVE AI on August 12, 2026 at 17:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security update or hotfix for ColdFusion released by Adobe in the referenced advisory.
  • Restrict network exposure to the ColdFusion service by allowing inbound traffic only from trusted IP addresses and enforce firewall rules to limit access to necessary ports.
  • Run ColdFusion under a least‑privileged account and ensure that the service does not have elevated OS permissions that would magnify the impact of code execution.
  • If the vulnerable feature is not required, consider disabling it or removing its exposure to untrusted input; otherwise, validate and sanitize all incoming data before it is processed by ColdFusion.

Generated by OpenCVE AI on August 12, 2026 at 17:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe coldfusion
CPEs cpe:2.3:a:adobe:coldfusion:2023:-:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update10:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update11:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update12:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update13:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update14:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update15:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update16:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update17:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update18:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update19:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update1:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update20:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update21:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update22:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update2:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update3:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update4:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update5:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update6:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update7:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update8:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update9:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:-:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update10:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update11:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update1:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update2:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update3:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update4:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update5:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update6:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update7:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update8:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update9:*:*:*:*:*:*
Vendors & Products Adobe coldfusion

Thu, 13 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025
Vendors & Products Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025

Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.
Title ColdFusion | Heap-based Buffer Overflow (CWE-122)
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Coldfusion Coldfusion 2023 Coldfusion 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:34:05.552Z

Reserved: 2026-05-21T15:28:38.146Z

Link: CVE-2026-48440

cve-icon Vulnrichment

Updated: 2026-08-12T13:36:34.588Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:01.330

Modified: 2026-08-28T00:18:01.920

Link: CVE-2026-48440

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T04:15:02Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow