CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-48276

Critical · CVSS 10.0

Adobe ColdFusion — Unrestricted File Upload leading to Remote Code Execution (CWE-434)

CVSS
10.0
nvd
EPSS
KEV
No
Class
other
CWE-434

Description

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Search profile — drives PoC discovery

Symbols ColdFusionfile uploadarbitrary code executionAPSB26-68multipartcffilecffileuploadupload handlerdangerous file type
Keywords CVE-2026-48276ColdFusion unrestricted file upload RCEColdFusion 2025 file upload vulnerabilityColdFusion 2023 arbitrary file uploadAPSB26-68 proof of conceptColdFusion CWE-434 exploitColdFusion unrestricted upload PoCAdobe ColdFusion RCE 2026
Versions: ColdFusion 2025 <= 2025.9, ColdFusion 2023 <= 2023.20

References

Status: enriched · ingested 2026-07-01T00:00:14.000Z · profiled 2026-07-01T18:30:14.000Z