CVE-2026-75746
Adobe Security Bulletin APSB26-119 — Coldfusion
Beschreibung
ColdFusion ist von einer Schwachstelle betroffen, die auf eine unzureichende Neutralisierung spezieller Elemente in einem SQL-Befehl ('SQL-Injection') zurückzuführen ist und zur willkürlichen Codeausführung im Kontext des aktuellen Benutzers führen könnte. Ein Angreifer mit hohen Privilegien könnte diese Schwachstelle ausnutzen, um beliebigen Code auszuführen. Die Ausnutzung dieses Problems erfordert keine Interaktion des Benutzers. Der Geltungsbereich wurde geändert.
Metriken
Weakness-Klassen (CWE)
CWE-89Base
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- CVE Modified2026-09-09 10:21 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-75746","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI… → {"id":"CVE-2026-75746","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- CVE Modified2026-09-09 05:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-75746","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- New CVE Received2026-09-08 20:18 UTC· psirt@adobe.com
- Description: ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
- CVSS V3.1: AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- CWE: CWE-89
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/75xxx/CVE-2026-75746.json">CVE-2026-75746</a>
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
Adobe
ColdFusion2023.0.23
Adobe
ColdFusion2025.0.12
Adobe
ColdFusion2023 <2023.0.24
Adobe
ColdFusion2025 <2025.0.13
Quellen & Referenzen
Verknüpfte CVEs
- CVE-2026-76190
ColdFusion ist von einer Schwachstelle betroffen, die auf eine unsachgemäße Neutralisierung von Direktiven in dynamisch ausgewertetem Cod…
highCVSSv3 8.6 - CVE-2026-76002
ColdFusion ist von einer reflektierten Cross-Site Scripting (XSS)-Sicherheitslücke betroffen.
mediumCVSSv3 6.1 - CVE-2026-76000
ColdFusion ist von einer Schwachstelle der unkontrollierten Ressourcenverbrauch betroffen, die zu einem Anwendungs-Denial-of-Service führ…
mediumCVSSv3 6.5 - CVE-2026-75999
ColdFusion ist von einer Schwachstelle aufgrund unzureichender Eingabevalidierung betroffen, die zur willkürlichen Codeausführung im Kont…
highCVSSv3 8.4 - CVE-2026-75998
ColdFusion ist von einer Schwachstelle im Zugriffskontrollmechanismus betroffen, die zu einem willkürlichen Dateisystem-Lesen führen könnte.
highCVSSv3 7.5 - CVE-2026-75993
ColdFusion ist von einer reflektierten Cross-Site Scripting (XSS)-Sicherheitslücke betroffen.
highCVSSv3 8.5 - CVE-2026-48273
ColdFusion ist von einer Schwachstelle betroffen, die auf eine unsachgemäße Neutralisierung von Direktiven in dynamisch ausgewertetem Cod…
criticalCVSSv3 9.9