CVE-2026-12257

Versions of Mura CMS prior to 10.0.712 contain a critical remote code execution (RCE) vulnerability. The flaw is located in the endpoint “/index.cfm/_api/json/v1/default”, where the “method” parameter in POST requests is not properly validated or sanitised before being processed by the ColdFusion engine. As a result, a remote attacker could exploit this vulnerability to inject and execute arbitrary CFML (ColdFusion Markup Language) expressions and instantiate malicious Java objects, thereby compromising the system’s security.
CVSS

No CVSS.

Configurations

No configuration.

History

13 Jul 2026, 14:16

Type Values Removed Values Added
CWE CWE-79 CWE-94

13 Jul 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-13 12:16

Updated : 2026-07-13 18:05


NVD link : CVE-2026-12257

Mitre link : CVE-2026-12257

CVE.ORG link : CVE-2026-12257


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')