Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-48321: ColdFusion: Unauthorized Access to Sensitive Data

CVE-2026-48321
Summary

A security issue in ColdFusion could allow an attacker to access sensitive data or make changes without permission. This could happen without the user's knowledge or action. To protect your system, update ColdFusion to the latest version.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
adobe coldfusion 2023
2025
cpe:2.3:a:adobe:coldfusion:2023:-:*:*:*:*:*:*
Original title
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write acces...
Original description
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of this issue does not require user interaction. Scope is changed.
nvd CVSS3.1 9.3
Vulnerability type
CWE-863 Incorrect Authorization
Published: 14 Jul 2026 · Updated: 20 Jul 2026 · First seen: 14 Jul 2026