Server-Side Request Forgery Vulnerability in Adobe ColdFusion Products
CVE-2026-48285
8.6HIGH
What is CVE-2026-48285?
Adobe ColdFusion versions 2025.9 and 2023.20 are affected by a Server-Side Request Forgery (SSRF) vulnerability that enables attackers to bypass security measures, potentially allowing unauthorized read access to sensitive information. This vulnerability requires no user interaction to exploit, presenting a significant risk and altering the expected security scope.
Affected Version(s)
ColdFusion 0 <= 2023.20