Executive brief
Adobe ColdFusion, a platform for developing and deploying web applications, is affected by a security flaw that allows unauthorized access to data. An attacker with basic user credentials can bypass built-in security protections to read or modify sensitive information without any interaction from a legitimate user. This could lead to data breaches or unauthorized changes to application content and configuration.
Technical details
An improper input validation vulnerability (CWE-20) exists in Adobe ColdFusion versions 2023.19, 2025.8, and earlier. The flaw allows a remote attacker with low-level privileges to bypass security feature restrictions. By providing specially crafted input, the attacker can gain unauthorized read and write access to the system. The attack is carried out over the network, requires no user interaction, and has a high impact on data confidentiality and integrity. Adobe has addressed this in security bulletin APSB26-64.
Affected products
- Adobe ColdFusion 2023.19 and earlier, 2025.8 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory