VDB

GCVE-110-NCSC-2026-241

GCVE-110-NCSC-2026-241
Advisory PublishedCVSS 9.0/10
Vulnetix · Advisory published July 16, 2026
ColdFusion contains an Incorrect Authorization vulnerability enabling arbitrary code execution within the current user's context without requiring user interaction, altering the execution scope.

Weaknesses (CWE)

CWE-863Incorrect AuthorizationCWE-306Missing Authentication for Critical FunctionCWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')CWE-94Improper Control of Generation of Code ('Code Injection')CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-613Insufficient Session ExpirationCWE-918Server-Side Request Forgery (SSRF)

Risk Scores

CVSS 3.1
9.0/10
Critical · CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
Adobevers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

77,041 records in the GCVE database · Updated August 7, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›