Junglewise Threat Intelligence

CVE-2026-48321: Adobe ColdFusion privilege escalation via incorrect authorization

CVE-2026-48321 · Severity: critical · CVSS 9.3 · Published 2026-07-14

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion, a platform for developing and deploying web applications, is affected by a security flaw that allows unauthorized users to gain elevated permissions. An attacker could exploit this to read or modify sensitive data without needing any interaction from a legitimate user. This could lead to a complete compromise of the application's data integrity and confidentiality.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in Adobe ColdFusion 2023 and 2025. The flaw allows an unauthenticated attacker on the adjacent network to bypass authorization checks, leading to privilege escalation. Successful exploitation grants the attacker unauthorized read and write access to the system. The vulnerability is particularly severe as it involves a scope change (S:C), meaning the impact can extend beyond the ColdFusion application itself to the underlying security scope. No user interaction is required for exploitation.

Affected products

  • Adobe ColdFusion 2025 <= 10
  • Adobe ColdFusion 2023 <= 21

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory: Adobe released security bulletin APSB26-82

References

Related threats