PT-2026-57807 · Mura Cms · Mura Cms

CVE-2026-12257

·

Published

2026-07-13

·

Updated

2026-07-15

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Mura CMS versions prior to 10.0.712
Description A remote code execution issue exists in the '/index.cfm/ api/json/v1/default' endpoint. The method parameter in POST requests is not properly validated or sanitized before being processed by the ColdFusion engine. This allows a remote attacker to inject and execute arbitrary CFML (ColdFusion Markup Language) expressions and instantiate malicious Java objects.
Recommendations Update to version 10.0.712. As a temporary workaround, restrict access to the '/index.cfm/ api/json/v1/default' endpoint or avoid using the method parameter in POST requests to this endpoint.

Fix

RCE

Code Injection

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12257

Affected Products

Mura Cms