Impact
An improper limitation of a pathname to a restricted directory (CWE-22) in Adobe ColdFusion allows an attacker to supply a specially crafted pathname that the server interprets outside the intended directory. The flaw can lead to arbitrary code execution in the context of the current user. Because the scope is changed, the compromise can affect the entire application and the underlying system.
Affected Systems
Adobe ColdFusion 2025.9, 2023.20, and all earlier releases are vulnerable unless patched or upgraded.
Risk and Exploitability
The CVSS score of 10 and the lack of a user‑interaction requirement mean an attacker can ColdFusion instance. The EPSS score of 29% indicates a high likelihood of exploitation. The vulnerability is listed in the CISA KEV catalog, underscoring real‑world exploitation risk. Because the scope is changed, a successful exploit can affect the entire application and the underlying operating system, making the threat more severe than a simple file‑inclusion. The attack vector is likely a remote web request that submits a crafted pathname to a ColdFusion resource.
OpenCVE Enrichment