Impact
An improper limitation of a pathname to a restricted directory (CWE-22) in Adobe ColdFusion allows an attacker to supply a specially crafted pathname that the server interprets outside the intended directory. The flaw can lead to arbitrary code execution in the context of the current user. Because the scope is changed, the compromise can affect the entire application and the underlying system.
Affected Systems
Adobe ColdFusion 2025.9, 2023.20, and all earlier releases are vulnerable unless patched or upgraded.
Risk and Exploitability
The CVSS score of 10 and the absence of a user-interaction requirement mean an attacker can exploit a ColdFusion instance remotely by sending a specially crafted request. The EPSS score of 99% indicates a very high likelihood of exploitation, and the vulnerability is listed in the CISA KEV catalog, underscoring real‑world exploitation risk. Because the scope is changed, a successful exploit can affect the entire application and the underlying operating system, making the threat more severe than a simple file‑inclusion. The attack vector is likely a remote web request that submits a crafted pathname to a ColdFusion resource.
OpenCVE Enrichment