Junglewise Threat Intelligence

CVE-2026-48276: Adobe ColdFusion unrestricted file upload

CVE-2026-48276 · Severity: critical · CVSS 10 · Published 2026-06-30

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion, a platform used for building and deploying web applications, contains a critical security flaw that allows unauthorized individuals to upload malicious files to the server. If exploited, an attacker could take complete control of the server, potentially leading to the theft of sensitive data or a total disruption of business operations. This attack can be carried out over the internet without any interaction from legitimate users.

Technical details

Adobe ColdFusion is vulnerable to an unrestricted file upload flaw (CWE-434) in versions 2025.9, 2023.20, and prior. The vulnerability exists because the application fails to properly validate or restrict the types of files uploaded to the server, allowing an attacker to upload executable scripts (such as .cfm or .jsp files). An unauthenticated remote attacker can exploit this by sending a specially crafted request to the server, leading to arbitrary code execution with the privileges of the ColdFusion service account. The vulnerability is rated critical with a CVSS score of 10.0 due to the lack of required user interaction and the potential for a full system compromise.

Affected products

  • Adobe ColdFusion 2025.9, 2023.20 and earlier

Timeline

  • 2026-06-30: advisory: Initial disclosure by Adobe and NVD

References

Related threats