CVE-2026-48376

Summary

is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction.

Affected Software

VendorProductVersion RangeStatus
AdobeColdFusion 20250 <= 2025.0.11affected
AdobeColdFusion 20252025.0.12unaffected
AdobeColdFusion 20230 <= 2023.0.22affected
AdobeColdFusion 20232023.0.23unaffected

Weaknesses

  • CWE-116: Improper Encoding or Escaping of Output (CWE-116)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References