Versions of Mura CMS prior to 10.0.712 contain a critical remote code execution (RCE) vulnerability. The flaw is located in the endpoint “/index.cfm/_api/json/v1/default”, where the “method” parameter in POST requests is not properly validated or sanitised before being processed by the ColdFusion engine. As a result, a remote attacker could exploit this vulnerability to inject and execute arbitrary CFML (ColdFusion Markup Language) expressions and instantiate malicious Java objects, thereby compromising the system’s security.
CVSS
No CVSS.
References
Configurations
No configuration.
History
13 Jul 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-94 |
13 Jul 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-13 12:16
Updated : 2026-07-13 18:05
NVD link : CVE-2026-12257
Mitre link : CVE-2026-12257
CVE.ORG link : CVE-2026-12257
JSON object : View
Products Affected
No product.
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
