CVE-2026-48385: ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48385?
The severity of CVE-2026-48385 is rated high with a score of 7.7.
What type of vulnerability is CVE-2026-48385?
CVE-2026-48385 is classified as an OS Command Injection vulnerability.
How can CVE-2026-48385 be exploited by an attacker?
A low-privileged attacker can exploit CVE-2026-48385 to bypass security measures and gain unauthorized access.
What systems are affected by CVE-2026-48385?
CVE-2026-48385 affects ColdFusion applications that inadequately neutralize special elements in OS commands.
How do I fix CVE-2026-48385?
To mitigate CVE-2026-48385, you should apply the latest security patches provided by Adobe for ColdFusion.