CVE-2026-48273

9.9

Adobe · ColdFusion

Adobe ColdFusion is vulnerable to Eval Injection, allowing low-privileged, authenticated attackers to achieve arbitrary remote code execution without user interaction.

Executive summary

Adobe ColdFusion is susceptible to a critical Eval Injection vulnerability that allows low-privileged attackers to execute arbitrary code, posing a severe risk of full system compromise.

Vulnerability

This vulnerability is an Eval Injection (CWE-95) flaw where improper neutralization of directives in dynamically evaluated code allows an attacker with low privileges to execute arbitrary commands. The vulnerability is accessible via the network and does not require user interaction to trigger.

Business impact

The ability for a low-privileged attacker to execute arbitrary code grants them the capacity to take full control over the affected server. This could lead to complete data exfiltration, unauthorized modification of sensitive business information, and potential lateral movement within the corporate network, warranting the critical CVSS score of 9.9.

Remediation

Immediate Action: Update Adobe ColdFusion 2025 to version 13 or later, and Adobe ColdFusion 2023 to version 24 or later, as specified in the official Adobe security advisory.

Proactive Monitoring: Review application and system access logs for anomalous requests, specifically targeting patterns associated with dynamic code evaluation or unusual command execution.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block malicious payloads targeting dynamic evaluation functions in ColdFusion environments.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical severity of this arbitrary code execution vulnerability, immediate patching is required to secure the environment. Organizations must prioritize applying the provided updates to their ColdFusion instances to prevent potential unauthorized access and system compromise.

More Adobe CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources