← back
CVE-2023-26359

Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution

CVSS 9.8 CRITICALEPSS 17.9%● KEVCWE-502
In short

Adobe ColdFusion has a critical flaw that allows attackers to run malicious code on affected servers by sending specially crafted data. No user interaction is needed—attackers can exploit this remotely.

Technical detail

ColdFusion versions 2018 Update 15 and earlier, and 2021 Update 5 and earlier are vulnerable to unsafe deserialization (CWE-502) of untrusted input, enabling remote code execution in the context of the application user without requiring authentication or user interaction.

Summary generated and translated by AI from the official description.
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Adobe · ColdFusion

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →