Junglewise Threat Intelligence

CVE-2026-48325: Adobe ColdFusion missing authentication for critical function

CVE-2026-48325 · Severity: critical · CVSS 9.3 · Published 2026-07-14

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion, a platform used for building and deploying web applications, contains a security flaw where critical functions do not require proper identity verification. An attacker on the same local network could exploit this to run unauthorized commands and take control of the server. This could lead to the theft of sensitive data or a complete compromise of the application environment without any user interaction.

Technical details

Adobe ColdFusion (versions 2023 and 2025) is vulnerable to a missing authentication check (CWE-306) for a critical function. The vulnerability allows an unauthenticated attacker with adjacent network access to execute arbitrary code in the context of the user running the ColdFusion service. The exploit requires no user interaction and results in a 'Scope Changed' (S:C) impact under CVSS 3.1, indicating the attacker can impact components beyond the ColdFusion application itself. Adobe has released security updates (APSB26-82) to address this issue; users are advised to upgrade to ColdFusion 2025 Update 11 or ColdFusion 2023 Update 22.

Affected products

  • Adobe ColdFusion 2025 <= 10
  • Adobe ColdFusion 2023 <= 21

Timeline

  • 2026-07-14: advisory: Adobe published security bulletin APSB26-82
  • 2026-07-14: disclosed: CVE-2026-48325 published to NVD

References

Related threats