Impact
ColdFusion versions 2023.18, 2025.6 and all earlier releases contain a path‑traversal flaw that permits attackers to read files outside the intended directory. The vulnerability enables remote arbitrary file access without user interaction.
Affected Systems
The affected product is Adobe ColdFusion, all versions up to 2025.6 inclusive, including the releases listed in the CPE set such as 2023 and 2025 with update branches.
Risk and Exploitability
The CVSS score of 8.6 reflects a high‑severity risk, and the EPSS of 29% indicates a relatively high probability that the vulnerability will be exploited. Based on the description, it is inferred that the flaw can be triggered by a crafted request to a ColdFusion file‑access endpoint, allowing an unauthenticated attacker to obtain sensitive files remotely. The vulnerability is not currently catalogued in CISA KEV, but the combination of high severity, broad impact, and exploit likelihood warrants prompt mitigation.
OpenCVE Enrichment