CVE-2026-34635: ColdFusion | Use of Hard-coded Cryptographic Key (CWE-321)
is affected by a Use of Hard-coded Cryptographic Key vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34635?
CVE-2026-34635 has a severity rating of high with a score of 8.4.
What impact does CVE-2026-34635 have on security?
CVE-2026-34635 could allow a low-privileged attacker to bypass security measures and gain unauthorized read and write access.
How do I fix CVE-2026-34635?
To fix CVE-2026-34635, update to the latest version of ColdFusion that addresses the hard-coded cryptographic key vulnerability.
What are the potential consequences of ignoring CVE-2026-34635?
Ignoring CVE-2026-34635 may lead to unauthorized access and potential security breaches in ColdFusion applications.
Who is affected by CVE-2026-34635?
All users of ColdFusion could be affected by CVE-2026-34635 due to the use of a hard-coded cryptographic key.