Junglewise Threat Intelligence

CVE-2026-27282: Adobe ColdFusion security feature bypass via improper input validation

CVE-2026-27282 · Severity: high · CVSS 7.5 · Published 2026-04-14

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion, a platform for building and deploying web applications, is affected by a security flaw that allows attackers to bypass built-in security protections. By exploiting this weakness, an unauthorized individual could gain access to restricted areas of the application. Successful exploitation requires a user to perform a specific action, such as clicking a malicious link.

Technical details

An improper input validation vulnerability (CWE-20) exists in Adobe ColdFusion versions 2023.18, 2025.6, and earlier. The flaw resides in how the application validates incoming data, which can be manipulated to bypass security feature controls. While the CVSS vector indicates a network attack vector with no privileges required, the advisory notes that user interaction is a prerequisite for successful exploitation. An attacker successfully leveraging this vulnerability could achieve unauthorized access to protected components. Adobe has released security updates (APSB26-38) to address this issue.

Affected products

  • Adobe ColdFusion 2023.18, 2025.6 and earlier

Timeline

  • 2026-04-14: disclosed
  • 2026-04-14: advisory: Adobe published security bulletin APSB26-38

References

Related threats