CVE-2026-21279: ColdFusion | Improper Input Validation (CWE-20)
Published Aug 11, 2026
·Updated
is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access. Exploitation of this issue does not require user interaction.
Affected Software
1 affected component
Adobe ColdFusion
Event History
Aug 11, 2026
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-21279?
CVE-2026-21279 has a high severity rating of 8.2.
2
What type of vulnerability is CVE-2026-21279?
CVE-2026-21279 is classified as an Improper Input Validation vulnerability.
3
How can an attacker exploit CVE-2026-21279?
An attacker can exploit CVE-2026-21279 to bypass security features and gain unauthorized read and limited write access.
4
Does exploitation of CVE-2026-21279 require user interaction?
Exploitation of CVE-2026-21279 does not require user interaction.
5
What impact does CVE-2026-21279 have on security measures?
CVE-2026-21279 can lead to a bypass of security measures, allowing unauthorized access.