Impact
This vulnerability is a form of eval injection that allows a low‑privileged attacker to execute arbitrary code in the context of the current user. The flaw is caused by improper neutralization of directives in dynamically evaluated ColdFusion code, and it can be exploited without any user interaction. The result is a compromise of confidentiality, integrity, and availability on affected systems.
Affected Systems
Adobe ColdFusion 2023 and 2025 are affected. The vulnerability is present in all deployed instances of these product lines unless already updated beyond the release dates documented by Adobe.
Risk and Exploitability
The CVSS score of 9.9 indicates a critical severity. The EPSS score is 2%, which reflects a low but nonzero exploitation probability. The lack of a need for user interaction and the scope change make the vulnerability highly attractive to attackers. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote or network‑based, where an attacker can supply malicious code via a web interface or other input mechanism that is processed by an eval‑like function.
OpenCVE Enrichment