Executive brief
Adobe ColdFusion is an enterprise application server used to build and deploy dynamic web applications. A vulnerability in input validation could allow a low-privileged attacker to gain elevated privileges and unauthorized access to data by tricking a victim into opening a malicious file, potentially compromising sensitive business applications and data.
Technical details
This is an improper input validation vulnerability in Adobe ColdFusion that can be exploited to achieve privilege escalation. The vulnerability requires user interaction—specifically, a victim must open a malicious file to trigger the exploit. A low-privileged attacker can leverage this flaw to gain unauthorized read and write access to the system. The scope of the vulnerability is changed, meaning an attacker may be able to impact resources beyond their privilege level. No public exploit code is currently known to be in active use.
Affected products
- Adobe ColdFusion <UNKNOWN>
Timeline
- 2026-08-11: disclosed