CVE-2026-48384

Adobe Security Bulletin APSB26-90 — Coldfusion

Beschreibung

ColdFusion ist von einer Schwachstelle aufgrund unzureichender Eingabevalidierung betroffen, die zu einem Anwendungs-Denial-of-Service führen könnte. Ein Angreifer mit hohen Privilegien könnte diese Schwachstelle ausnutzen, um den Dienst abzustellen und eine Denial-of-Service-Bedingung herbeizuführen. Die Ausnutzung dieses Problems erfordert keine Benutzerinteraktion.

Metriken

Severity
medium
kein öffentlicher PoC bekannt
4.9
Quelle: nvd-v3
51.1 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.7 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-11 16:30 UTC
CWE-20

Weakness-Klassen (CWE)

  • CWE-20Class

    Improper Input Validation

    The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-08-28 00:17 UTC· psirt@adobe.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/48xxx/CVE-2026-48384.json">CVE-2026-48384</a>
    • Reference: https://helpx.adobe.com/security/products/coldfusion/apsb26-90.html
    • Reference: https://helpx.adobe.com/security/products/coldfusion/apsb26-90.html
    • Reference Type: https://helpx.adobe.com/security/products/coldfusion/apsb26-90.html Types: Vendor Advisory
  2. CVE Modified2026-08-11 18:17 UTC· psirt@adobe.com
    • Affected: ColdFusion 2025, ColdFusion 2023ColdFusion 2025, ColdFusion 2023
  3. New CVE Received2026-08-11 17:18 UTC· psirt@adobe.com
    • Affected: ColdFusion 2025, ColdFusion 2023
    • Description: ColdFusion is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker with high privileges could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
    • CVSS V3.1: AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
    • CWE: CWE-20

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • adobe

    coldfusion

  • Adobe

    ColdFusion2023 <2023.0.24

  • Adobe

    ColdFusion2025 <2025.0.13

Quellen & Referenzen

Verknüpfte CVEs

IDCVE-2026-48384