CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-48322

Critical · CVSS 9.9

Adobe ColdFusion — Code Injection (CWE-94) leading to Arbitrary Code Execution

CVSS
9.9
nvd
EPSS
0.90%
56th pct
KEV
No
Class
other
CWE-94

Description

ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Search profile — drives PoC discovery

Symbols ColdFusionAPSB26-82code injectionarbitrary code executionCWE-94
Keywords CVE-2026-48322Adobe ColdFusioncode injectionRCEAPSB26-82ColdFusion exploitColdFusion PoCimproper code generationColdFusion arbitrary code execution
Versions: <UNKNOWN>

References

Status: enriched · ingested 2026-07-15T18:00:20.000Z · profiled 2026-07-15T18:30:20.000Z