Impact
ColdFusion versions 2023.19, 2025.8 and earlier contain an Improper Input Validation flaw that could lead to arbitrary code execution in the context of the current user. An attacker with high privileges can exploit this vulnerability to run arbitrary code. The component that is vulnerable is, by default, confined to an administrative network zone. Exploitation does not require user interaction, and the scope of the vulnerability has been altered to reflect a broader privilege escalation risk. The primary impact is remote code execution. This flaw is classified as CWE‑20.
Affected Systems
Adobe ColdFusion versions 2023.19, 2025.8 and all earlier releases are affected. The vulnerability applies to the core ColdFusion engine regardless of deployment size or architecture. Administrators should verify that their Adobe ColdFusion installations match these versions before applying remediation.
Risk and Exploitability
The CVSS base score of 8.4 categorizes this as high severity, and the EPSS score is < 1% but the lack of user interaction requirement suggests that remote exploitation is possible. The vulnerability is not listed in the CISA KEV catalog, but its high impact necessitates immediate attention. Attackers could remotely send crafted input to the application, triggering code execution under the current user context and potentially escalating privileges if the application runs with elevated rights.
OpenCVE Enrichment