Impact
ColdFusion versions 2023.19, 2025.8 and all earlier releases contain a path‑traversal flaw that allows an attacker to bypass directory restrictions and load a file from outside the intended sandbox. The vulnerable component is restricted to an administrative network zone by default, but the flaw still permits arbitrary code execution in the context of the current user when a victim opens a malicious file. The vulnerability requires user interaction – a crafted file must be delivered and opened – and the scope of the vulnerability has been changed by Adobe. The flaw is an indirect exploitation scenario that typically arises through malicious documents or web downloads.
Affected Systems
All deployments of Adobe ColdFusion up to and including version 2023.19 and 2025.08 are affected, including all update releases listed in the CPE data. This encompasses the 2023 releases from update1 through update19 and the 2025 releases from update1 through update8.
Risk and Exploitability
The flaw carries a CVSS score of 8.8, indicating high severity. The EPSS score of 3 % indicates a low but nonzero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a victim to open a crafted malicious file, so the primary attack vector is indirect and typically involves file delivery such as an email attachment or a web download. The risk is focused on confidentiality and integrity because of unauthorized file access and potential code execution.
OpenCVE Enrichment