Executive brief
Adobe ColdFusion, a platform used for building and deploying web applications, is affected by a critical security flaw. An attacker could use this vulnerability to take full control of the server and execute malicious commands. This could lead to the theft of sensitive data, complete service disruption, or unauthorized access to internal corporate systems.
Technical details
Adobe ColdFusion is vulnerable to SQL Injection (CWE-89) due to improper neutralization of special elements used in SQL commands. The vulnerability is reachable over the network and does not require user interaction, though it requires high-level administrative privileges (PR:H). Successful exploitation allows for a scope change (S:C), potentially leading to arbitrary code execution in the context of the service user. Adobe has released updates for ColdFusion 2023 and 2025 to address this issue.
Affected products
- Adobe ColdFusion 2025 <= 10
- Adobe ColdFusion 2023 <= 21
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory: Adobe advisory APSB26-82 published