CVE-2026-48376: ColdFusion | Improper Encoding or Escaping of Output (CWE-116)
is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48376?
CVE-2026-48376 has a medium severity rating of 5.4.
How do I fix CVE-2026-48376?
To address CVE-2026-48376, ensure that output is properly encoded or escaped to prevent security feature bypass.
What type of vulnerability is CVE-2026-48376?
CVE-2026-48376 is classified as an Improper Encoding or Escaping of Output vulnerability.
What kind of risk does CVE-2026-48376 pose to my system?
CVE-2026-48376 allows a low-privileged attacker to potentially gain limited unauthorized write access.
What applications are affected by CVE-2026-48376?
CVE-2026-48376 affects Adobe ColdFusion and its handling of output.