CVE-2026-47929: ColdFusion | Incorrect Authorization (CWE-863)
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could exploit this vulnerability to gain elevated access or control over the victim's account or session. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ColdFusionto a version that resolves this vulnerability.Fixed in 2023.19 - Upgrade
Upgrade
ColdFusionto a version that resolves this vulnerability.Fixed in 2025.8 - Compensating control
Ensure the ColdFusion vulnerable component remains restricted to an administrative network zone (it is restricted by default).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47929?
CVE-2026-47929 has a high severity rating of 8.4.
What vulnerability does CVE-2026-47929 address?
CVE-2026-47929 addresses an Incorrect Authorization vulnerability in ColdFusion.
How can I fix CVE-2026-47929?
To fix CVE-2026-47929, update to the latest version of Adobe ColdFusion that addresses this vulnerability.
What could happen if CVE-2026-47929 is exploited?
Exploitation of CVE-2026-47929 could lead to arbitrary code execution and elevated access for an attacker.
Which versions of ColdFusion are affected by CVE-2026-47929?
CVE-2026-47929 affects Adobe ColdFusion versions 2023.19, 2025.8, and earlier.