CVE-2026-47931: ColdFusion | Improper Input Validation (CWE-20)
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ColdFusionto a version that resolves this vulnerability.Fixed in 2023.19 - Upgrade
Upgrade
ColdFusionto a version that resolves this vulnerability.Fixed in 2025.8 - Compensating control
Ensure the ColdFusion vulnerable component remains restricted to an administrative network zone by default (keep it accessible only from the administrative network zone).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47931?
CVE-2026-47931 has a high severity score of 8.4.
How do I fix CVE-2026-47931?
To fix CVE-2026-47931, upgrade to a newer version of Adobe ColdFusion that addresses the improper input validation vulnerability.
What versions of ColdFusion are affected by CVE-2026-47931?
CVE-2026-47931 affects ColdFusion versions 2023.19, 2025.8, and earlier.
What type of vulnerability is CVE-2026-47931?
CVE-2026-47931 is classified as an Improper Input Validation vulnerability.
Can exploitation of CVE-2026-47931 occur without user interaction?
Yes, exploitation of CVE-2026-47931 does not require any user interaction.