CVE-2026-48321
Critical · CVSS 9.3Adobe ColdFusion — Incorrect Authorization / Privilege Escalation (CWE-863)
- CVSS
- 9.3
- nvd
- EPSS
- 0.77%
- 52th pct
- KEV
- No
- Class
- other
- CWE-863
Description
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.
Search profile — drives PoC discovery
Symbols ColdFusionAPSB26-82privilege escalationauthorization bypassread write accessscope changed
Keywords CVE-2026-48321ColdFusion privilege escalationColdFusion incorrect authorizationColdFusion authorization bypassAPSB26-82ColdFusion CWE-863ColdFusion unauthorized access PoC
Versions: <UNKNOWN>
References
Status: enriched · ingested 2026-07-15T18:00:20.000Z · profiled 2026-07-15T18:30:20.000Z