XML External Entity injection in ColdFusion - CVE-2026-47960
Published: June 9, 2026
ColdFusion
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper restriction of xml external entity reference in ColdFusion when parsing XML input. A remote attacker can trick the victim into processing crafted XML content to disclose sensitive information.
User interaction is required.