CVE-2026-48328: ColdFusion | Improper Input Validation (CWE-20)
ColdFusion is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48328?
CVE-2026-48328 has a severity rating of 7.7, categorized as high.
How do I fix CVE-2026-48328?
To fix CVE-2026-48328, upgrade to the patched version of Adobe ColdFusion provided by Adobe.
What type of vulnerability is CVE-2026-48328?
CVE-2026-48328 is classified as an Improper Input Validation vulnerability, leading to potential security feature bypass.
Who is affected by CVE-2026-48328?
CVE-2026-48328 affects users of Adobe ColdFusion who may be exposed to unauthorized access due to this vulnerability.
What impact does CVE-2026-48328 have on systems?
CVE-2026-48328 could allow low-privileged attackers to bypass security measures and gain unauthorized read access.