Executive brief
Adobe ColdFusion, a platform for building and deploying web applications, is affected by a security vulnerability that could allow an attacker to execute unauthorized code. By tricking a user into opening a malicious file, an attacker could inject scripts into web pages to take control of user sessions or access sensitive account information. This could lead to a total compromise of the affected user's data and unauthorized actions performed on their behalf.
Technical details
Adobe ColdFusion contains an improper input validation vulnerability (CWE-20) in versions 2025.9, 2023.20, and earlier. The flaw allows for arbitrary code execution or script injection when a victim is enticed into opening a specially crafted malicious file. While the attack vector is network-based, it requires user interaction (UI:R) to succeed. Successful exploitation enables an attacker to execute code in the context of the current user or perform cross-site scripting (XSS) style attacks to hijack sessions, as indicated by the changed scope (S:C) in the CVSS metric. Adobe has released security bulletin APSB26-68 to address this issue.
Affected products
- Adobe ColdFusion 2025.9, 2023.20 and earlier
Timeline
- 2026-06-30: disclosed
- 2026-06-30: advisory: Adobe security bulletin APSB26-68 published