CVE-2026-48322

Summary

ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Affected Software

VendorProductVersion RangeStatus
AdobeColdFusion 20250 <= 10affected
AdobeColdFusion 202511unaffected
AdobeColdFusion 20230 <= 21affected
AdobeColdFusion 202322unaffected

Weaknesses

  • CWE-94: Improper Control of Generation of Code ('Code Injection') (CWE-94)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References