Impact
ColdFusion versions 2023.19, 2025.8 and any earlier releases contain an improper input validation flaw that allows an attacker to execute arbitrary code with the privileges of the current user. The vulnerable component is restricted to an administrative network zone by default, and the flaw does not require user interaction. Because the scope is changed, the vulnerability could empower an attacker to gain full control of the application or the underlying operating system once they reach the administrative zone.
Affected Systems
Adobe ColdFusion products: versions 2023.19, 2025.8 and any earlier releases; newer releases beyond 2025.8 are not affected according to the advisory.
Risk and Exploitability
The CVSS score of 9.6 indicates critical severity, and the EPSS score of 2% suggests a low probability that automated scanners may target this vulnerability. The lack of a listed KEV entry suggests the vulnerability is not yet widely documented in known exploit kits. The attack vector is inferred to be remote network-based, as the flaw can be triggered through crafted input to exposed ColdFusion services without any user interaction, making it suitable for automated exploitation.
OpenCVE Enrichment