Junglewise Threat Intelligence

CVE-2026-47933: Adobe ColdFusion stored XSS in form fields

CVE-2026-47933 · Severity: medium · CVSS 4.8 · Published 2026-06-09

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion, a platform for building enterprise web applications, is affected by a security flaw that allows attackers to save malicious scripts into the system. An attacker with low-level access can inject these scripts into form fields, which then execute in the browsers of other users, such as administrators, when they view the affected page. This could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive session information.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe ColdFusion (versions 2023.19, 2025.8 and earlier) due to improper neutralization of input during web page generation (CWE-79). A low-privileged attacker can exploit this by injecting malicious JavaScript into vulnerable form fields. The payload is stored on the server and executed in the context of a victim's browser session when they navigate to the page containing the injected content. According to the CVSS vector, the attack requires user interaction and is limited to the adjacent network. Successful exploitation results in a change of scope, potentially allowing the attacker to access sensitive browser-based data or perform actions as the victim user.

Affected products

  • Adobe ColdFusion 2023 2023.19 and earlier
  • Adobe ColdFusion 2025 2025.8 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory: Adobe APSB26-64 published

References

Related threats