OS Command Injection Vulnerability in Adobe ColdFusion
CVE-2026-48385
7.7HIGH
What is CVE-2026-48385?
Adobe ColdFusion is vulnerable to an OS Command Injection, which may allow low-privileged attackers to bypass security features and gain unauthorized write access to the system. Exploiting this vulnerability does not require any user interaction, leading to a potential compromise of system integrity.
Affected Version(s)
ColdFusion 2023 0 <= 2023.0.22
ColdFusion 2023 0 <= 2023.0.22
ColdFusion 2025 0 <= 2025.0.11