CVE-2026-47930: ColdFusion | Improper Input Validation (CWE-20)
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47930?
CVE-2026-47930 has a severity rating of high with a score of 8.1.
How do I fix CVE-2026-47930?
To fix CVE-2026-47930, users should update their Adobe ColdFusion software to the latest versions that contain security patches.
What types of attacks can CVE-2026-47930 facilitate?
CVE-2026-47930 can facilitate unauthorized read and write access through a security feature bypass by low-privileged attackers.
What is the impact of CVE-2026-47930?
The impact of CVE-2026-47930 includes potential exploitation resulting in unauthorized access to sensitive data and functions within ColdFusion.
Which versions of ColdFusion are affected by CVE-2026-47930?
CVE-2026-47930 affects Adobe ColdFusion versions 2023.19, 2025.8, and earlier.