VDB
CVE-2026-48329
CVE-2026-48329
PUBLISHED
CVSS 2.7 LOW
Reported by adobe · Published July 14, 2026
ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.
Risk Scores
CVSS 3.1
2.7
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Adobe | ColdFusion 2025 | 0, 11 |
| Adobe | ColdFusion 2023 | 0, 22 |
| Adobe | ColdFusion 2023 | 22, 0, 22 |
| Adobe | ColdFusion 2025 | 0, 11, 0 |
Timeline
- Jul 14, 2026 CVE Published
- Jul 15, 2026 Coalition ESS Score
- Jul 15, 2026 CVE Updated
- Jul 16, 2026 Security Advisory