{"id":"CVE-2023-26359","details":"Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.","modified":"2026-03-14T11:59:33.376217Z","published":"2023-03-23T20:15:15.167Z","references":[{"type":"ADVISORY","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-26359"},{"type":"FIX","url":"https://helpx.adobe.com/security/products/coldfusion/apsb23-25.html"}],"affected":[{"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"2018-NA"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update1"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update10"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update11"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update12"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update13"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update14"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update15"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update2"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update3"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update4"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update5"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update6"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update7"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update8"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update9"}]},{"events":[{"introduced":"0"},{"last_affected":"2021-NA"}]},{"events":[{"introduced":"0"},{"last_affected":"2021-update1"}]},{"events":[{"introduced":"0"},{"last_affected":"2021-update2"}]},{"events":[{"introduced":"0"},{"last_affected":"2021-update3"}]},{"events":[{"introduced":"0"},{"last_affected":"2021-update4"}]},{"events":[{"introduced":"0"},{"last_affected":"2021-update5"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-26359.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}