CVE-2026-21269

Adobe Security Bulletin APSB26-90 — Coldfusion

Beschreibung

Es ist von einer gespeicherten Cross-Site Scripting (XSS)-Sicherheitslücke betroffen, die von einem Angreifer mit geringen Berechtigungen ausgenutzt werden könnte, um schädliche Skripte in anfällige Formularfelder einzufügen. Bösartiges JavaScript kann im Browser eines Opfers ausgeführt werden, wenn sie auf die Seite mit dem anfälligen Feld zugreifen. Der Geltungsbereich wurde geändert.

Metriken

Severity
medium
kein öffentlicher PoC bekannt
5.4
Quelle: nvd-v3
40.9 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.5 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-11 16:30 UTC
CWE-79

Weakness-Klassen (CWE)

  • CWE-79Base

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-09-08 20:17 UTC· psirt@adobe.com
    • Description: is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.ColdFusion is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/21xxx/CVE-2026-21269.json">CVE-2026-21269</a>
    • Reference: https://helpx.adobe.com/security/products/coldfusion/apsb26-119.html
    • Reference: https://helpx.adobe.com/security/products/coldfusion/apsb26-90.html
  2. CVE Modified2026-08-28 00:16 UTC· psirt@adobe.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/21xxx/CVE-2026-21269.json">CVE-2026-21269</a>
    • Reference: https://helpx.adobe.com/security/products/coldfusion/apsb26-90.html
    • Reference: https://helpx.adobe.com/security/products/coldfusion/apsb26-90.html
    • Reference Type: https://helpx.adobe.com/security/products/coldfusion/apsb26-90.html Types: Vendor Advisory
  3. CVE Modified2026-08-11 18:17 UTC· psirt@adobe.com
    • Affected: ColdFusion 2025, ColdFusion 2023ColdFusion 2025, ColdFusion 2023
  4. CVE Modified2026-08-11 18:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-21269","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  5. New CVE Received2026-08-11 17:17 UTC· psirt@adobe.com
    • Affected: ColdFusion 2025, ColdFusion 2023
    • Description: is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
    • CVSS V3.1: AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
    • CWE: CWE-79

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • adobe

    coldfusion

  • Adobe

    ColdFusion2023 <2023.0.24

  • Adobe

    ColdFusion2025 <2025.0.13

Quellen & Referenzen

Verknüpfte CVEs

IDCVE-2026-21269