CVE-2026-48329
ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.
- Vendor
- Adobe, Adobe
- Product
- ColdFusion 2023, ColdFusion 2025
- Provider severity
- LOW
- Conflicts
- 1