Impact
The vulnerability is an improper input validation flaw that allows an attacker to bypass security controls. This can lead to unauthorized reading of protected data and restricted write operations that modify configuration or application files. The weakness is classified as CWE‑20, indicating input checks are missing or inadequate.
Affected Systems
Vendors impacted include Adobe ColdFusion 2023 and Adobe ColdFusion 2025. No further version details are specified in the CNA data, but any installation of these product lines is potentially vulnerable.
Risk and Exploitability
With a CVSS score of 8.2, the flaw poses a high severity risk. The EPSS score of less than 1% indicates a low probability of exploitation in the wild at this time, and it is not listed in the CISA KEV catalog. Because exploitation does not require user interaction, the likely attack vector involves remote users sending crafted requests to the ColdFusion server to trigger the validation bypass.
OpenCVE Enrichment