CVE-2026-76190

ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-08 20:18

Updated : 2026-09-10 14:17


NVD link : CVE-2026-76190

Mitre link : CVE-2026-76190

CVE.ORG link : CVE-2026-76190


JSON object : View

Products Affected

No product.

CWE
CWE-95

Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')