CVE-2026-48384: ColdFusion | Improper Input Validation (CWE-20)
Published Aug 11, 2026
·Updated
ColdFusion is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker with high privileges could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Affected Software
1 affected component
Adobe ColdFusion
Event History
Aug 11, 2026
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-48384?
The severity of CVE-2026-48384 is medium, rated at 4.9.
2
What type of vulnerability is CVE-2026-48384?
CVE-2026-48384 is characterized as an Improper Input Validation vulnerability.
3
How does CVE-2026-48384 affect ColdFusion applications?
CVE-2026-48384 can result in an application denial-of-service, leading to a crash of the application.
4
Who is at risk with CVE-2026-48384?
An attacker with high privileges can exploit CVE-2026-48384 to crash a ColdFusion application.
5
What is the potential impact of exploiting CVE-2026-48384?
Exploiting CVE-2026-48384 could lead to a denial-of-service condition for the affected application.