EIP-2026-104151
PRE-CVEAdobe ColdFusion versions 2018_15 (and earlier) and 2021_5 and earlier - Arbitrary File Read
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104151. PoCs published by Youssef Muhammad.
AI-analyzed exploit summary This exploit leverages a deserialization vulnerability in Adobe ColdFusion to read arbitrary files by crafting a malicious JSON payload sent to a vulnerable CFC endpoint. The exploit checks for a specific error response pattern to extract file contents.
Description
Adobe ColdFusion versions 2018_15 (and earlier) and 2021_5 and earlier - Arbitrary File Read
Exploits (1)
This exploit leverages a deserialization vulnerability in Adobe ColdFusion to read arbitrary files by crafting a malicious JSON payload sent to a vulnerable CFC endpoint. The exploit checks for a specific error response pattern to extract file contents.