Junglewise Threat Intelligence

CVE-2026-48320: Adobe ColdFusion reflected XSS

CVE-2026-48320 · Severity: high · CVSS 8.5 · Published 2026-07-14

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion, a platform for building and deploying web applications, is affected by a security vulnerability that could allow an attacker to take over user sessions. By tricking a user into opening a malicious file, an attacker can execute unauthorized scripts in the user's browser. This could lead to the theft of sensitive login information or unauthorized actions performed on behalf of the user.

Technical details

Adobe ColdFusion (versions 2023 and 2025) contains a reflected Cross-Site Scripting (XSS) vulnerability (CWE-79) due to improper neutralization of input during web page generation. The attack vector is classified as 'Adjacent', meaning the attacker must be on the same local network or subnetwork as the victim. Exploitation requires user interaction, specifically that a victim opens a malicious file provided by the attacker. Successful exploitation allows for the execution of arbitrary JavaScript in the context of the victim's browser session, which can lead to session hijacking or unauthorized data access. Adobe has released updates to address this issue in ColdFusion 2025 (version 11) and ColdFusion 2023 (version 22).

Affected products

  • Adobe ColdFusion 2025 <= 10
  • Adobe ColdFusion 2023 <= 21

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats