CVE-2026-48322

Adobe Security Bulletin APSB26-82 — Coldfusion

criticalEPSS 1.2 %

Beschreibung

ColdFusion ist von einer Schwachstelle aufgrund der unsachgemäßen Steuerung der Codeerzeugung ('Code-Injektion') betroffen, die zur willkürlichen Ausführung von Code im Kontext des aktuellen Benutzers führen könnte. Ein Angreifer mit geringen Berechtigungen könnte diese Schwachstelle ausnutzen, um beliebigen Code auszuführen. Die Ausnutzung dieses Problems erfordert keine Interaktion des Benutzers. Der Geltungsbereich wurde geändert.

Metriken

Severity
critical
kein öffentlicher PoC bekannt
9.9
Quelle: nvd-v3
65.6 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
1.2 %
Moderat — Modell schätzt 1-10 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-07-14 21:16 UTC
CWE-94

Weakness-Klassen (CWE)

  • CWE-94Base

    Improper Control of Generation of Code ('Code Injection')

    The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-08-28 00:17 UTC· psirt@adobe.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/48xxx/CVE-2026-48322.json">CVE-2026-48322</a>
    • Reference: https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html
    • Reference: https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html
    • Reference Type: https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html Types: Vendor Advisory
  2. CVE Modified2026-08-04 23:16 UTC· psirt@adobe.com
    • Description: ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
    • CVSS V3.1: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
    • CVSS V3.1: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
  3. Initial Analysis2026-07-15 17:56 UTC· nvd@nist.gov
    • CVSS V3.1: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
    • CPE Configuration: OR *cpe:2.3:a:adobe:coldfusion:2023:update1:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:-:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update2:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update3:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update4:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update5:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update7:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update6:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update8:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update9:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update11:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update10:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update12:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2025:-:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update13:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2025:update1:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update14:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2025:update2:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update15:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2025:update3:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update16:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2025:update4:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2025:update5:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update18:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2025:update6:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update17:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update19:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2025:update7:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2025:update8:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update20:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2025:update9:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update21:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2025:update10:*:*:*:*:*:*
    • Reference Type: Adobe Systems Incorporated: https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html Types: Vendor Advisory

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • adobe

    coldfusion

Quellen & Referenzen

Verknüpfte CVEs

Verknüpfte Empfehlungen

IDCVE-2026-48322