CVE-2026-48376

Adobe Security Bulletin APSB26-90 — Coldfusion

mediumEPSS 15 %

Beschreibung

Dieses System ist von einer Schwachstelle aufgrund unzureichender Kodierung oder Entschlüsselung der Ausgabe betroffen, die zu einem Umgehen von Sicherheitsfunktionen führen könnte. Ein Angreifer mit geringen Berechtigungen könnte diese Schwachstelle ausnutzen, um Sicherheitsmaßnahmen zu umgehen und eingeschränkten unbefugten Schreibzugriff zu erlangen, was eine begrenzte Beeinträchtigung der Verfügbarkeit verursacht. Die Ausnutzung dieses Problems erfordert keine Benutzerinteraktion.

Metriken

Severity
medium
kein öffentlicher PoC bekannt
5.4
Quelle: nvd-v3
96.6 %
Kritisch — CVE liegt im obersten Fünftel aller heute bewerteten CVEs (Rang ≥ 80 %).
15.5 %
Erhöht — Modell schätzt 10-50 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-11 16:30 UTC
CWE-116

Weakness-Klassen (CWE)

  • CWE-116Class

    Improper Encoding or Escaping of Output

    The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-08-28 00:17 UTC· psirt@adobe.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/48xxx/CVE-2026-48376.json">CVE-2026-48376</a>
    • Reference: https://helpx.adobe.com/security/products/coldfusion/apsb26-90.html
    • Reference: https://helpx.adobe.com/security/products/coldfusion/apsb26-90.html
    • Reference Type: https://helpx.adobe.com/security/products/coldfusion/apsb26-90.html Types: Vendor Advisory
  2. CVE Modified2026-08-11 19:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-48376","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  3. CVE Modified2026-08-11 18:17 UTC· psirt@adobe.com
    • Affected: ColdFusion 2025, ColdFusion 2023ColdFusion 2025, ColdFusion 2023
  4. New CVE Received2026-08-11 17:17 UTC· psirt@adobe.com
    • Affected: ColdFusion 2025, ColdFusion 2023
    • Description: is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction.
    • CVSS V3.1: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
    • CWE: CWE-116

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • adobe

    coldfusion

  • Adobe

    ColdFusion2023 <2023.0.24

  • Adobe

    ColdFusion2025 <2025.0.13

Quellen & Referenzen

Verknüpfte CVEs

IDCVE-2026-48376