CVE-2026-27306:
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Attacker requires elevated privileges. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Score
A numerical rating that indicates how dangerous this vulnerability is.
8.4HighA numerical rating that indicates how dangerous this vulnerability is.
- Published Date:Apr 14, 2026
- CISA KEV Date:*No Data*
- Industries Affected:20
Exploitability
- Score:1.7
- Attack Vector:ADJACENT_NETWORK
- Attack Complexity:LOW
- Privileges Required:HIGH
- User Interaction:NONE
- Scope:CHANGED
Impact
- Score:6.0
- Confidentiality Impact:HIGH
- Integrity Impact:HIGH
- Availability Impact:HIGH
Description Preview
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Attacker requires elevated privileges. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Industries Affected
Below is a list of industries most commonly impacted or potentially at risk based on intelligence.
Low