CVE-2026-48384 PUBLISHED

ColdFusion | Improper Input Validation (CWE-20)

Assigner: adobe
Reserved: 21.05.2026 Published: 11.08.2026 Updated: 11.08.2026

ColdFusion is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker with high privileges could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 4.9

Product Status

Vendor Adobe
Product ColdFusion 2025
Versions Default: affected
  • affected from 0 to 2025.0.11 (incl.)
  • Version 2025.0.12 is unaffected
Vendor Adobe
Product ColdFusion 2023
Versions Default: affected
  • affected from 0 to 2023.0.22 (incl.)
  • Version 2023.0.23 is unaffected

References

Problem Types

  • Improper Input Validation (CWE-20) CWE