Description
is affected by a Use of Hard-coded Cryptographic Key vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-08-11
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability involves a hard‑coded cryptographic key, identified as CWE‑321. An attacker with low privileges can exploit this flaw to bypass security controls, gaining unauthorized read and write capabilities. The flaw can be triggered without user interaction, and the scope of impact is broadened due to changes in affected components.

Affected Systems

Adobe offers ColdFusion 2023 and ColdFusion 2025 as the affected products. All releases of these versions that contain the hard‑coded key are susceptible; the issue is mitigated only in the latest patched releases.

Risk and Exploitability

The CVSS score of 8.4 signifies a high severity level, while an EPSS score of less than 1% indicates a low probability of being actively exploited, and the vulnerability is not listed in the KEV catalog. The attack can be carried out from a low‑privileged context within the application environment, without requiring user interaction; once executed, the attacker can read and modify protected data, posing a significant threat to confidentiality, integrity, and availability.

Generated by OpenCVE AI on August 12, 2026 at 21:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Adobe ColdFusion 2023 or 2025 releases that remove the hard‑coded cryptographic key.
  • Replace any remaining hard‑coded keys or sensitive configuration values in application code with secure storage mechanisms such as environment variables or encrypted vaults.
  • Verify that authentication, authorization, and encryption settings enforce least privilege and prevent use of weak or static keys.

Generated by OpenCVE AI on August 12, 2026 at 21:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe coldfusion
CPEs cpe:2.3:a:adobe:coldfusion:2023:-:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update10:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update11:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update12:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update13:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update14:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update15:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update16:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update17:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update18:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update19:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update1:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update20:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update21:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update22:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update2:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update3:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update4:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update5:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update6:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update7:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update8:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update9:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:-:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update10:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update11:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update1:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update2:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update3:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update4:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update5:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update6:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update7:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update8:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update9:*:*:*:*:*:*
Vendors & Products Adobe coldfusion

Thu, 13 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025
Vendors & Products Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025

Wed, 12 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description is affected by a Use of Hard-coded Cryptographic Key vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction. Scope is changed.
Title ColdFusion | Use of Hard-coded Cryptographic Key (CWE-321)
Weaknesses CWE-321
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Adobe Coldfusion Coldfusion 2023 Coldfusion 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:34:16.753Z

Reserved: 2026-03-30T17:30:36.491Z

Link: CVE-2026-34635

cve-icon Vulnrichment

Updated: 2026-08-12T16:40:55.640Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:17:57.963

Modified: 2026-08-28T00:17:17.327

Link: CVE-2026-34635

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T04:30:06Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key