ColdFusion | Improper Input Validation (CWE-20)
Summary
| CVE | CVE-2026-48315 |
|---|---|
| State | PUBLISHED |
| Assigner | adobe |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-30 16:16:55 UTC |
| Updated | 2026-08-28 00:17:47 UTC |
| Description | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. |
Risk And Classification
Primary CVSS: v3.1 9.3 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
EPSS: 0.010280000 probability, percentile 0.612260000 (date 2026-08-30)
Problem Types: CWE-20 | CWE-20 Improper Input Validation (CWE-20)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 9.3 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N |
| 3.1 | CNA | CVSS | 9.3 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
ChangedConfidentiality
HighIntegrity
HighAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Adobe | Coldfusion | 2023 | - | All | All |
| Application | Adobe | Coldfusion | 2023 | update1 | All | All |
| Application | Adobe | Coldfusion | 2023 | update10 | All | All |
| Application | Adobe | Coldfusion | 2023 | update11 | All | All |
| Application | Adobe | Coldfusion | 2023 | update12 | All | All |
| Application | Adobe | Coldfusion | 2023 | update13 | All | All |
| Application | Adobe | Coldfusion | 2023 | update14 | All | All |
| Application | Adobe | Coldfusion | 2023 | update15 | All | All |
| Application | Adobe | Coldfusion | 2023 | update16 | All | All |
| Application | Adobe | Coldfusion | 2023 | update17 | All | All |
| Application | Adobe | Coldfusion | 2023 | update18 | All | All |
| Application | Adobe | Coldfusion | 2023 | update19 | All | All |
| Application | Adobe | Coldfusion | 2023 | update2 | All | All |
| Application | Adobe | Coldfusion | 2023 | update20 | All | All |
| Application | Adobe | Coldfusion | 2023 | update3 | All | All |
| Application | Adobe | Coldfusion | 2023 | update4 | All | All |
| Application | Adobe | Coldfusion | 2023 | update5 | All | All |
| Application | Adobe | Coldfusion | 2023 | update6 | All | All |
| Application | Adobe | Coldfusion | 2023 | update7 | All | All |
| Application | Adobe | Coldfusion | 2023 | update8 | All | All |
| Application | Adobe | Coldfusion | 2023 | update9 | All | All |
| Application | Adobe | Coldfusion | 2025 | - | All | All |
| Application | Adobe | Coldfusion | 2025 | update1 | All | All |
| Application | Adobe | Coldfusion | 2025 | update2 | All | All |
| Application | Adobe | Coldfusion | 2025 | update3 | All | All |
| Application | Adobe | Coldfusion | 2025 | update4 | All | All |
| Application | Adobe | Coldfusion | 2025 | update5 | All | All |
| Application | Adobe | Coldfusion | 2025 | update6 | All | All |
| Application | Adobe | Coldfusion | 2025 | update7 | All | All |
| Application | Adobe | Coldfusion | 2025 | update8 | All | All |
| Application | Adobe | Coldfusion | 2025 | update9 | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Adobe | ColdFusion 2025 | affected 9 custom | Not specified |
| CNA | Adobe | ColdFusion 2025 | unaffected 10 custom | Not specified |
| CNA | Adobe | ColdFusion 2023 | affected 20 custom | Not specified |
| CNA | Adobe | ColdFusion 2023 | unaffected 21 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| helpx.adobe.com/security/products/coldfusion/apsb26-68.html | [email protected] | helpx.adobe.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.