Impact
An Incorrect Authorization flaw in Adobe ColdFusion permits a low‑privileged attacker to gain unauthorized read and write capabilities, effectively escalating privileges within the application. The vulnerability can be exploited without any user interaction, allowing the attacker to alter data and potentially compromise the confidentiality, integrity, and availability of the affected system.
Affected Systems
The flaw affects Adobe ColdFusion versions 2023 and 2025. No specific sub‑versions are listed, so all builds of these releases are considered vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. While the exact attack vector is not detailed in the advisory, the description implies that exploitation can occur remotely through the application's web interface or API, as user interaction is not required. An attacker who can send crafted requests may bypass authorization checks and perform privileged actions.
OpenCVE Enrichment