Junglewise Threat Intelligence

CVE-2026-47929: Adobe ColdFusion incorrect authorization in arbitrary code execution

CVE-2026-47929 · Severity: high · CVSS 8.4 · Published 2026-06-09

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion, a platform for building and deploying web applications, is affected by a security flaw that could allow an attacker to take full control of the server. A high-privileged user on the local network could bypass security checks to run unauthorized commands or access sensitive session data. This could lead to a complete compromise of the application and the data it manages without any interaction from other users.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in Adobe ColdFusion versions 2023.19, 2025.8, and earlier. The flaw allows a high-privileged attacker with adjacent network access to bypass authorization logic and execute arbitrary code in the context of the current user. Because the vulnerability results in a scope change (S:C), an exploit can impact components beyond the immediate security scope of the ColdFusion environment. No user interaction is required for successful exploitation. Adobe has addressed this issue in security bulletin APSB26-64.

Affected products

  • Adobe ColdFusion 2023 2023.19 and earlier
  • Adobe ColdFusion 2025 2025.8 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory: Adobe security bulletin APSB26-64 published

References

Related threats