Sceawere
Vulnerability Detail
CVE-2026-71386UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Administrative Network Cross-Site Scripting Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 7h ago
- Vendor
- Adobe
- Product
- ColdFusion 2025
- Attack Type
- Cross-site Scripting (XSS) (CWE-79)
- Vector String
- CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-08-11T17:19:13.723Z",
"pubdate": "2026-08-11T17:19:13.723Z",
"executiveSummary": "An arbitrary code execution vulnerability involving Cross-site Scripting (XSS) has been identified within the affected product. This security flaw permits malicious actors to execute arbitrary code within the execution context of the currently authenticated user session. The realization of this vulnerability presents severe risk implications, potentially leading to unauthorized administrative actions, session hijacking, or compromise of sensitive data accessible to the victim.\nRegarding attacker capabilities, an external or adjacent adversary must leverage specific delivery mechanisms to reach the vulnerable component. However, the exploitation vectors are naturally bounded by default configurations, as the vulnerable component is strictly restricted to an administrative network zone. Consequently, successful exploitation requires targeted user interaction; specifically, a victimized administrative user must open a maliciously crafted file supplied by the attacker. Upon file execution within the browser or application context, the embedded payload triggers, resulting in a changed security scope and arbitrary code execution.\nOrganizations deploying the affected product must account for the cross-site scripting vector, network zone constraints, and the mandatory user interaction prerequisite when evaluating overall organizational risk and prioritizing defensive countermeasures.",
"technicalDetails": "The vulnerability stems from improper neutralization of user-supplied data or file inputs processed by the application, manifesting as a Cross-site Scripting (XSS) vulnerability. When a victim opens a malicious file, the application improperly parses or renders the contents without adequate sanitization or context-aware encoding, allowing malicious script instructions to be injected into the user interface or processing pipeline.\nThe attack flow proceeds as follows: First, an attacker crafts a malicious file designed to carry an XSS payload capable of arbitrary code execution. Second, the attacker delivers this file to a target user operating within the administrative network zone. Third, the victim interacts with the system by opening the malicious file. Fourth, the vulnerable component processes the file inputs, failing to validate or encode the malicious data securely. Fifth, the injected script executes within the context of the current user session. Because the scope is changed, the impact extends beyond the immediate component boundaries, granting the attacker the ability to execute arbitrary code under the privileges of the active user.\nNetwork exposure is constrained by default, as the vulnerable component resides exclusively within an administrative network zone, limiting direct external reachability to authenticated or internally positioned actors. Authentication and privilege requirements depend on access to the administrative network zone and the necessary interaction to open the malicious file. The post-exploitation impact includes arbitrary code execution in the context of the victim, potentially enabling attackers to pivot further into the administrative environment, manipulate administrative functions, or extract confidential session data."
}