CVE-2026-48324
Adobe ColdFusion 2023 is vulnerable to a SQL injection that allows an attacker with high privileges to execute arbitrary code. The flaw occurs when the software builds SQL commands from user input without proper sanitization. No user interaction is required, and the vulnerability can affect all components of the application.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Adobe ColdFusion 2023 (all released versions).
Real-world impact
An attacker who can send specially crafted requests to a ColdFusion 2023 instance could run any code on the server with the privileges of the current user, potentially taking full control of the system.
Why this severity
The CVSS score of 9.1 reflects that the attack is network reachable, requires low effort, and can change the scope of the system. The high privileges needed and the lack of user interaction make it a critical threat.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 14, 2026 · 19d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 29, 2026 · 4d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- helpx.adobe.com/security/products/coldfusio…vendor advisory