Impact
ColdFusion versions up to 2025.9 and 2023.20 allow an attacker to upload any file type without restriction, enabling execution of that file in the context of the current user. Because the vulnerability changes scope, it is inferred that the attacker could potentially gain privileges beyond the initial user and run arbitrary code. No user interaction is required.
Affected Systems
The affected products are Adobe ColdFusion software versions 2025.9, 2023.20 and all earlier releases. The vulnerability is present in all those releases, regardless of deployment environment.
Risk and Exploitability
The CVSS score of 10 highlights the vulnerability as critical. Since execution can occur without any user action, an attacker could exploit a publicly reachable upload endpoint to deliver a malicious script or binary. The EPSS score of 5% indicates a moderate probability that attackers will exploit the vulnerability, while the absence from KEV suggests no known public exploitation yet. However, the ability to change scope and run arbitrary code makes it highly dangerous.
OpenCVE Enrichment