All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-48385
HIGHpublished 2026-08-11 17:18 UTC · 1 day ago · modified 2026-08-12 21:03 UTC
7.7
CVSS / 10
// description
ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction. Scope is changed.
// weaknesses (CWE)
- CWE-78