Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-48324: ColdFusion SQL Injection Vulnerability Allows Code Execution
CVE-2026-48324
CVE-2026-48324
Summary
ColdFusion software is at risk of being exploited by malicious code that can execute arbitrary actions with the current user's permissions. This vulnerability can be exploited without user interaction, making it a priority to update the software to a secure version.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| adobe | coldfusion 2025 | <= 10 |
| adobe | coldfusion 2023 | <= 21 |
| adobe | coldfusion |
2023 2025 cpe:2.3:a:adobe:coldfusion:2023:-:*:*:*:*:*:* |
Original title
ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the c...
Original description
ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
nvd CVSS3.1
9.1
Vulnerability type
CWE-89
SQL Injection
Published: 14 Jul 2026 · Updated: 20 Jul 2026 · First seen: 14 Jul 2026