Executive brief
Adobe ColdFusion, a platform for building and deploying web applications, is affected by a security flaw that allows attackers to bypass built-in security protections. By exploiting this weakness, an unauthorized individual could gain access to restricted areas of the application. Successful exploitation requires a user to perform a specific action, such as clicking a malicious link.
Technical details
An improper input validation vulnerability (CWE-20) exists in Adobe ColdFusion versions 2023.18, 2025.6, and earlier. The flaw resides in how the application validates incoming data, which can be manipulated to bypass security feature controls. While the CVSS vector indicates a network attack vector with no privileges required, the advisory notes that user interaction is a prerequisite for successful exploitation. An attacker successfully leveraging this vulnerability could achieve unauthorized access to protected components. Adobe has released security updates (APSB26-38) to address this issue.
Affected products
- Adobe ColdFusion 2023.18, 2025.6 and earlier
Timeline
- 2026-04-14: disclosed
- 2026-04-14: advisory: Adobe published security bulletin APSB26-38