CVE-2026-27282: ColdFusion | Improper Input Validation (CWE-20)
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue requires user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27282?
CVE-2026-27282 is considered a high severity vulnerability due to its potential for a security feature bypass.
How do I fix CVE-2026-27282?
To fix CVE-2026-27282, upgrade your Adobe ColdFusion to version 2023.19 or 2025.7 or later to mitigate the vulnerability.
Who is affected by CVE-2026-27282?
CVE-2026-27282 affects Adobe ColdFusion versions up to and including 2023.18 and 2025.6.
What types of attacks can exploit CVE-2026-27282?
CVE-2026-27282 can be exploited by attackers to bypass security measures and gain unauthorized access to affected systems.
What CWE does CVE-2026-27282 relate to?
CVE-2026-27282 is related to CWE-20, which pertains to improper input validation.