OS Command Injection Vulnerability in Adobe ColdFusion
CVE-2026-48362

10CRITICAL

Key Information:

Vendor

Adobe

Vendor
CVE Published:
11 August 2026

What is CVE-2026-48362?

Adobe ColdFusion is vulnerable to an OS Command Injection that allows an attacker to execute arbitrary code within the context of the current user. This vulnerability occurs due to improper handling of special elements, facilitating potential exploitation without user interaction. Users of affected ColdFusion versions should consider implementing security updates to mitigate this risk.

Affected Version(s)

ColdFusion 2023 0 <= 2023.0.22

ColdFusion 2023 0 <= 2023.0.22

ColdFusion 2025 0 <= 2025.0.11

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.