CVE-2026-48385

Adobe Security Bulletin APSB26-90 — Coldfusion

Beschreibung

ColdFusion ist von einer Schwachstelle betroffen, die auf eine unzureichende Neutralisierung spezieller Elemente in einem Betriebssystembefehl ('OS Command Injection') zurückzuführen ist und zu einem Umgehen von Sicherheitsfunktionen führen könnte. Ein Angreifer mit geringen Berechtigungen könnte diese Schwachstelle ausnutzen, um Sicherheitsmaßnahmen zu umgehen und unbefugten Schreibzugriff zu erhalten. Die Ausnutzung dieses Problems erfordert keine Benutzerinteraktion. Der Geltungsbereich wurde geändert.

Metriken

Severity
high
kein öffentlicher PoC bekannt
7.7
Quelle: nvd-v3
65.6 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
1.2 %
Moderat — Modell schätzt 1-10 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-11 16:30 UTC
CWE-78

Weakness-Klassen (CWE)

  • CWE-78Base

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-08-28 00:17 UTC· psirt@adobe.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/48xxx/CVE-2026-48385.json">CVE-2026-48385</a>
    • Reference: https://helpx.adobe.com/security/products/coldfusion/apsb26-90.html
    • Reference: https://helpx.adobe.com/security/products/coldfusion/apsb26-90.html
    • Reference Type: https://helpx.adobe.com/security/products/coldfusion/apsb26-90.html Types: Vendor Advisory
  2. CVE Modified2026-08-11 18:17 UTC· psirt@adobe.com
    • Affected: ColdFusion 2025, ColdFusion 2023ColdFusion 2025, ColdFusion 2023
  3. New CVE Received2026-08-11 17:18 UTC· psirt@adobe.com
    • Affected: ColdFusion 2025, ColdFusion 2023
    • Description: ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction. Scope is changed.
    • CVSS V3.1: AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
    • CWE: CWE-78

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • adobe

    coldfusion

  • Adobe

    ColdFusion2023 <2023.0.24

  • Adobe

    ColdFusion2025 <2025.0.13

Quellen & Referenzen

Verknüpfte CVEs

IDCVE-2026-48385