Junglewise Threat Intelligence

CVE-2026-48315: Adobe ColdFusion arbitrary code execution via improper input validation

CVE-2026-48315 · Severity: critical · CVSS 9.3 · Published 2026-06-30

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion, a platform for building and deploying web applications, is affected by a security vulnerability that could allow an attacker to execute unauthorized code. By tricking a user into opening a malicious file, an attacker could inject scripts into web pages to take control of user sessions or access sensitive account information. This could lead to a total compromise of the affected user's data and unauthorized actions performed on their behalf.

Technical details

Adobe ColdFusion contains an improper input validation vulnerability (CWE-20) in versions 2025.9, 2023.20, and earlier. The flaw allows for arbitrary code execution or script injection when a victim is enticed into opening a specially crafted malicious file. While the attack vector is network-based, it requires user interaction (UI:R) to succeed. Successful exploitation enables an attacker to execute code in the context of the current user or perform cross-site scripting (XSS) style attacks to hijack sessions, as indicated by the changed scope (S:C) in the CVSS metric. Adobe has released security bulletin APSB26-68 to address this issue.

Affected products

  • Adobe ColdFusion 2025.9, 2023.20 and earlier

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: advisory: Adobe security bulletin APSB26-68 published

References

Related threats