
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-48332 is a Server-Side Request Forgery (SSRF) vulnerability in Adobe ColdFusion that enables a low-privileged authenticated attacker to bypass security controls and gain unauthorized read access to protected resources. Disclosed on July 14, 2026, it affects ColdFusion 2025 (Update 10 and earlier) and ColdFusion 2023 (Update 21 and earlier) on all platforms. The vulnerability carries a CVSS v3.1 base score of 7.7 (High), with a changed scope indicating impact beyond the vulnerable component itself (Adobe Advisory, GitHub Advisory).
The vulnerability is classified as CWE-918 (Server-Side Request Forgery), where ColdFusion's web server receives and processes attacker-controlled URLs or requests without sufficiently validating the intended destination. An attacker with low-level network access and authenticated credentials can craft malicious requests that cause the ColdFusion server to make unauthorized outbound connections to internal or otherwise restricted resources, effectively bypassing security boundaries. No user interaction is required, and the attack complexity is low, making it straightforward to exploit once authenticated. The changed scope metric indicates that the SSRF can reach resources outside the ColdFusion application's direct security domain (GitHub Advisory, Adobe Advisory).
Successful exploitation results in a high confidentiality impact — an authenticated low-privileged attacker can read data they are not authorized to access by leveraging the ColdFusion server as a proxy to reach internal systems, metadata services, or other network resources. There is no integrity or availability impact. The changed scope means the attacker can potentially access resources on internal network segments that would otherwise be inaccessible, increasing the risk of lateral movement or sensitive data exposure (e.g., cloud instance metadata, internal APIs, or intranet services) (GitHub Advisory, Adobe Advisory).
Adobe has released security update APSB26-82 addressing this vulnerability. Organizations should upgrade ColdFusion 2025 to Update 11 or later, and ColdFusion 2023 to Update 22 or later (Adobe Advisory). As interim mitigations, administrators should restrict outbound network access from ColdFusion servers to only necessary destinations, implement network segmentation to limit the SSRF attack surface, and monitor for suspicious outbound HTTP/HTTPS requests originating from ColdFusion processes. Applying the vendor patch is the definitive remediation.
The CIS (Center for Internet Security) published an advisory noting multiple vulnerabilities in Adobe products patched in July 2026, including this SSRF issue. Check Point and Fortinet both added detection coverage for this CVE shortly after disclosure. No significant independent researcher commentary or social media discussion has been identified beyond standard vulnerability tracking and aggregation activity.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."