Unrestricted File Upload Vulnerability in Adobe ColdFusion
CVE-2026-48276

10CRITICAL

Key Information:

Vendor

Adobe

Vendor
CVE Published:
30 June 2026

What is CVE-2026-48276?

Adobe ColdFusion versions 2025.9 and 2023.20 are susceptible to a vulnerability that permits unrestricted file uploads of potentially dangerous file types. An attacker can exploit this flaw to execute arbitrary code within the context of the affected user. This vulnerability can be exploited without any user interaction, posing significant security risks to systems running these versions of ColdFusion.

Affected Version(s)

ColdFusion 0 <= 2023.20

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.