CVE-2026-48321: ColdFusion | Incorrect Authorization (CWE-863)
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to the vulnerable ColdFusion component to an administrative network zone (it is restricted to an administrative network zone by default).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48321?
CVE-2026-48321 has a critical severity score of 9.3.
How do I fix CVE-2026-48321?
To fix CVE-2026-48321, update Adobe ColdFusion to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2026-48321?
CVE-2026-48321 is an Incorrect Authorization vulnerability that can lead to privilege escalation.
What could be the consequences of exploiting CVE-2026-48321?
Exploiting CVE-2026-48321 could allow attackers to gain unauthorized read and write access.
Does CVE-2026-48321 require user interaction for exploitation?
No, exploitation of CVE-2026-48321 does not require user interaction.