Junglewise Threat Intelligence

CVE-2026-21273: Adobe ColdFusion improper input validation privilege escalation

CVE-2026-21273 · Severity: high · CVSS 8.7 · Published 2026-08-11

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion is an enterprise application server used to build and deploy dynamic web applications. A vulnerability in input validation could allow a low-privileged attacker to gain elevated privileges and unauthorized access to data by tricking a victim into opening a malicious file, potentially compromising sensitive business applications and data.

Technical details

This is an improper input validation vulnerability in Adobe ColdFusion that can be exploited to achieve privilege escalation. The vulnerability requires user interaction—specifically, a victim must open a malicious file to trigger the exploit. A low-privileged attacker can leverage this flaw to gain unauthorized read and write access to the system. The scope of the vulnerability is changed, meaning an attacker may be able to impact resources beyond their privilege level. No public exploit code is currently known to be in active use.

Affected products

  • Adobe ColdFusion <UNKNOWN>

Timeline

  • 2026-08-11: disclosed

References

Related threats