CVE-2026-48285: ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918)
ColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48285?
The severity of CVE-2026-48285 is classified as high with a score of 8.6.
How do I fix CVE-2026-48285?
To fix CVE-2026-48285, update your Adobe ColdFusion to the latest version that addresses this SSRF vulnerability.
What does CVE-2026-48285 exploit?
CVE-2026-48285 exploits a Server-Side Request Forgery (SSRF) vulnerability allowing unauthorized read access.
Which versions of ColdFusion are affected by CVE-2026-48285?
CVE-2026-48285 affects Adobe ColdFusion versions 2025.9, 2023.20 and earlier.
What could happen if CVE-2026-48285 is exploited?
If exploited, CVE-2026-48285 could result in a security feature bypass, allowing attackers unauthorized access.