Junglewise Threat Intelligence

CVE-2026-48327: Adobe ColdFusion incorrect authorization in code execution

CVE-2026-48327 · Severity: critical · CVSS 9 · Published 2026-07-14

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion, a platform for building and deploying web applications, is affected by a security flaw that allows an attacker to run unauthorized commands. If exploited, a malicious actor could take full control of the server, potentially leading to data theft or a complete shutdown of the application. This issue can be triggered without any interaction from a legitimate user.

Technical details

Adobe ColdFusion (versions 2023 and 2025) contains an incorrect authorization vulnerability (CWE-863). The flaw allows an attacker with low-privileged access on an adjacent network to bypass authorization checks and execute arbitrary code. Because the vulnerability results in a 'Scope Change' (S:C) in the CVSS metric, the impact can extend beyond the ColdFusion application itself to the underlying operating system or environment. No user interaction is required for exploitation. Adobe has released updates (ColdFusion 2025 Update 11 and ColdFusion 2023 Update 22) to address this issue.

Affected products

  • Adobe ColdFusion 2025 <= 10
  • Adobe ColdFusion 2023 <= 21

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats