Description
is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Published: 2026-08-11
Score: 8.8 High
EPSS: 6.6% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a classic cross‑site scripting weakness (CWE‑79) that can allow an attacker to inject arbitrary JavaScript which, when executed in a victim’s browser, can lead to code execution under the victim’s user context. The description explicitly states that the effect is “arbitrary code execution in the context of the current user.” Because the vulnerability is limited to the administrative network zone, the likelihood of exploitation in a public‑facing environment is low. The likely attack vector is inferred to be a social‑engineering scenario where an administrative user is tricked into opening a malicious file, after which the injected script runs with the user’s privileges.

Affected Systems

Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are affected. All build and update versions enumerated in the CPE list (2023 update1–update22, 2025 update1–update9, plus base releases) are vulnerable until a vendor fix is applied.

Risk and Exploitability

The CVSS score of 8.8 rates the issue as high severity, and the EPSS score of 7 % indicates a moderate likelihood of exploitation. The vulnerability is not in the CISA KEV catalog, suggesting it is not yet widely exploited. Because the flaw requires user interaction—an administrative user must open a crafted file in the default admin network zone—attacks are moderately difficult, but the impact of successful exploitation is full code execution under the victim’s privileges.

Generated by OpenCVE AI on August 24, 2026 at 22:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe ColdFusion patch or upgrade to a version in which the XSS issue is fixed.
  • Restrict access to the administrative network zone and enforce strict authentication and file‑type validation for administrative users.
  • Deploy a Web Application Firewall or content‑security policy that blocks reflected or stored XSS payloads, and monitor logs for attempts to inject malicious scripts.

Generated by OpenCVE AI on August 24, 2026 at 22:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe coldfusion
CPEs cpe:2.3:a:adobe:coldfusion:2023:-:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update10:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update11:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update12:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update13:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update14:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update15:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update16:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update17:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update18:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update19:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update1:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update20:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update21:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update22:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update2:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update3:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update4:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update5:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update6:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update7:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update8:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update9:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:-:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update10:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update11:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update1:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update2:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update3:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update4:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update5:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update6:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update7:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update8:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update9:*:*:*:*:*:*
Vendors & Products Adobe coldfusion

Thu, 13 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025
Vendors & Products Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025

Wed, 12 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Title ColdFusion | Cross-site Scripting (XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Coldfusion Coldfusion 2023 Coldfusion 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:34:00.619Z

Reserved: 2026-08-06T09:00:49.999Z

Link: CVE-2026-71386

cve-icon Vulnrichment

Updated: 2026-08-12T13:35:46.995Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:19:13.723

Modified: 2026-08-28T00:18:09.850

Link: CVE-2026-71386

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T22:30:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')