Impact
ColdFusion versions 2023.19, 2025.8, and all earlier releases are affected by an Incorrect Authorization flaw (CWE‑863) that permits a high‑privileged attacker to execute arbitrary code in the context of the current ColdFusion user without requiring any user interaction. The attacker can elevate access or control over the victim’s account or session. The vulnerability is limited to an administrative network zone by default, and the scope changes, but exploitation remains possible without user interaction.
Affected Systems
Adobe ColdFusion versions 2023.19, 2025.8, and all earlier releases are affected. Any installation of these versions should be assessed for current patch status.
Risk and Exploitability
The CVSS score of 8.4 categorizes this vulnerability as high severity. EPSS is 2%, indicating a lower likelihood of exploitation; however, it is not listed in the CISA KEV catalog. Exploitation does not require user interaction, and a high‑privileged attacker who can access the ColdFusion environment can exploit the flaw to execute arbitrary code or elevate privileges. The likely attack vector is an internal or super‑user scenario, inferred from the description that the flaw is exploitable without user interaction.
OpenCVE Enrichment