CVE-2026-48324: ColdFusion | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48324?
CVE-2026-48324 has a critical severity rating of 9.1.
What type of vulnerability is CVE-2026-48324?
CVE-2026-48324 is an SQL Injection vulnerability due to improper neutralization of special elements in an SQL command.
How does CVE-2026-48324 affect Adobe ColdFusion?
CVE-2026-48324 can lead to arbitrary code execution in the context of the current user using Adobe ColdFusion.
Do I need user interaction to exploit CVE-2026-48324?
No, exploiting CVE-2026-48324 does not require any user interaction.
What is the impact of exploiting CVE-2026-48324?
Exploitation of CVE-2026-48324 may lead to a change in scope, allowing attackers to execute arbitrary code.