Back to overview

CVE-2026-48285

HIGH
8.6
CVSS 3.1
Description
ColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.

Metadata

CVE ID
CVE-2026-48285
State
PUBLISHED
Assigner
adobe
Reserved
2026-05-21 15:28 UTC
Published
2026-06-30 15:12 UTC
Last updated
2026-06-30 16:45 UTC
Primary CWE
CWE-918
Server-Side Request Forgery (SSRF) (CWE-918)
Vendor / Product
Adobe / ColdFusion
Sources
cve.org  ·  NVD

Severity & Metrics

8.6 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
Adobe ColdFusion 0 ≤ 2023.20
Weakness (CWE)
CWESourceDescription
CWE-918 cna Server-Side Request Forgery (SSRF) (CWE-918)
CVSS scores (1)
ScoreSeverityVersionSourceVector
8.6 HIGH 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Back to overview