Junglewise Threat Intelligence

CVE-2026-48332: Adobe ColdFusion SSRF in security feature bypass

CVE-2026-48332 · Severity: high · CVSS 7.7 · Published 2026-07-14

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion, a platform for building and deploying web applications, is affected by a security vulnerability that allows attackers to bypass internal security controls. By exploiting this flaw, an attacker with low-level access can force the server to perform unauthorized requests, potentially leading to the exposure of sensitive internal data. This could result in the theft of confidential information or provide a foothold for further attacks within the corporate network.

Technical details

Adobe ColdFusion (versions 2023 and 2025) contains a Server-Side Request Forgery (SSRF) vulnerability, classified as CWE-918. The flaw allows a low-privileged attacker to send crafted requests from the vulnerable server, effectively bypassing security features such as firewalls or access control lists that protect internal resources. The vulnerability has a changed scope (S:C), meaning the impact extends beyond the ColdFusion environment to other systems reachable by the server. Exploitation requires network access and low-level authentication but does not require user interaction. Adobe has released patches (APSB26-82) to address this issue in ColdFusion 2023 Update 22 and ColdFusion 2025 Update 11.

Affected products

  • Adobe ColdFusion 2025 <= 10
  • Adobe ColdFusion 2023 <= 21

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats