Junglewise Threat Intelligence

CVE-2026-47930: Adobe ColdFusion security feature bypass via improper input validation

CVE-2026-47930 · Severity: high · CVSS 8.1 · Published 2026-06-09

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion, a platform for developing and deploying web applications, is affected by a security flaw that allows unauthorized access to data. An attacker with basic user credentials can bypass built-in security protections to read or modify sensitive information without any interaction from a legitimate user. This could lead to data breaches or unauthorized changes to application content and configuration.

Technical details

An improper input validation vulnerability (CWE-20) exists in Adobe ColdFusion versions 2023.19, 2025.8, and earlier. The flaw allows a remote attacker with low-level privileges to bypass security feature restrictions. By providing specially crafted input, the attacker can gain unauthorized read and write access to the system. The attack is carried out over the network, requires no user interaction, and has a high impact on data confidentiality and integrity. Adobe has addressed this in security bulletin APSB26-64.

Affected products

  • Adobe ColdFusion 2023.19 and earlier, 2025.8 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats