Junglewise Threat Intelligence

CVE-2026-48285: Adobe ColdFusion SSRF and security bypass

CVE-2026-48285 · Severity: high · CVSS 8.6 · Published 2026-06-30

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion, a platform for developing and deploying web applications, is affected by a security vulnerability that allows unauthorized access to internal resources. An attacker can exploit this flaw to bypass security protections and read sensitive information without needing any user interaction. This could lead to the exposure of internal data or configuration details that are normally protected from the public internet.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability (CWE-918) exists in Adobe ColdFusion versions 2025.9, 2023.20, and earlier. The flaw allows a remote, unauthenticated attacker to send crafted requests from the vulnerable server to internal or external resources. Because the 'Scope' is changed (S:C), the attacker can pivot from the ColdFusion application to access other services or metadata within the hosting environment that are not intended to be publicly accessible. This results in a high impact on confidentiality as the attacker can gain unauthorized read access to sensitive data. No user interaction is required for exploitation.

Affected products

  • Adobe ColdFusion 2025.9, 2023.20 and earlier

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: advisory

References

Related threats