CVE-2026-48283
Critical · CVSS 10.0Adobe ColdFusion — Unrestricted File Upload leading to Remote Code Execution (CWE-434)
- CVSS
- 10.0
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-434
Description
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Search profile — drives PoC discovery
Symbols ColdFusionfile uploadarbitrary code executionAPSB26-68cffilecffileuploadmultipart/form-datadangerous file type
Keywords CVE-2026-48283ColdFusion unrestricted file upload RCEAPSB26-68 PoCColdFusion 2025 file upload exploitColdFusion 2023 arbitrary code executionAdobe ColdFusion CWE-434ColdFusion webshell uploadColdFusion unauthenticated RCE 2026
Versions: ColdFusion 2025 <= 2025.9, ColdFusion 2023 <= 2023.20
References
Status: enriched · ingested 2026-07-01T00:00:14.000Z · profiled 2026-07-01T18:30:14.000Z