CVE-2026-48322
Critical · CVSS 9.9Adobe ColdFusion — Code Injection (CWE-94) leading to Arbitrary Code Execution
- CVSS
- 9.9
- nvd
- EPSS
- 0.90%
- 56th pct
- KEV
- No
- Class
- other
- CWE-94
Description
ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Search profile — drives PoC discovery
Symbols ColdFusionAPSB26-82code injectionarbitrary code executionCWE-94
Keywords CVE-2026-48322Adobe ColdFusioncode injectionRCEAPSB26-82ColdFusion exploitColdFusion PoCimproper code generationColdFusion arbitrary code execution
Versions: <UNKNOWN>
References
Status: enriched · ingested 2026-07-15T18:00:20.000Z · profiled 2026-07-15T18:30:20.000Z