Junglewise Threat Intelligence

CVE-2026-21269: Adobe ColdFusion stored XSS in form fields

CVE-2026-21269 · Severity: medium · CVSS 4.6 · Published 2026-08-11

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion is a server-side web application platform used to build dynamic websites and applications. A stored cross-site scripting vulnerability in form field handling allows attackers with low privileges to inject malicious scripts that execute in other users' browsers, potentially leading to session hijacking, credential theft, or unauthorized actions performed on behalf of legitimate users.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw in ColdFusion's form field processing. An attacker with low privileges can inject malicious JavaScript into vulnerable form fields, and the payload persists in the application (stored). When other users browse to pages containing the compromised field, the malicious script executes in their browsers with the same privileges as the victim user. The scope is changed, meaning the vulnerability affects resources beyond the vulnerable component itself. No authentication bypass is required—a low-privileged account is sufficient to inject the payload.

Affected products

  • Adobe ColdFusion

Timeline

  • 2026-08-11: disclosed

References

Related threats