CVE-2026-76190

Adobe Security Bulletin APSB26-119 — Coldfusion

Beschreibung

ColdFusion ist von einer Schwachstelle betroffen, die auf eine unsachgemäße Neutralisierung von Direktiven in dynamisch ausgewertetem Code ('Eval Injection') zurückzuführen ist und zur willkürlichen Ausführung von Code im Kontext des aktuellen Benutzers führen könnte. Ein Angreifer könnte diese Schwachstelle ausnutzen, um beliebigen Code auszuführen. Die Ausnutzung dieses Problems erfordert keine Interaktion mit dem Benutzer. Der Geltungsbereich wurde geändert.

Metriken

Severity
high
kein öffentlicher PoC bekannt
8.6
Quelle: nvd-v3
59.7 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
1.0 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-09-08 19:37 UTC
CWE-95

Weakness-Klassen (CWE)

  • CWE-95Variant

    Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')

    The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. "eval").

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-09-10 14:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-76190","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…{"id":"CVE-2026-76190","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
  2. CVE Modified2026-09-10 04:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-76190","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
  3. New CVE Received2026-09-08 20:18 UTC· psirt@adobe.com
    • Description: ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
    • CWE: CWE-95
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/76xxx/CVE-2026-76190.json">CVE-2026-76190</a>

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • Adobe

    ColdFusion2023.0.23

  • Adobe

    ColdFusion2025.0.12

  • Adobe

    ColdFusion2023 <2023.0.24

  • Adobe

    ColdFusion2025 <2025.0.13

Quellen & Referenzen

Verknüpfte CVEs

IDCVE-2026-76190