Description
ColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-06-30
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

ColdFusion versions 2025.9, 2023.20 and earlier contain a server‑side request forgery flaw (CWE‑918). The defect allows an attacker to craft outbound HTTP requests from the server to arbitrary destinations, bypassing built‑in security functions and returning data that should otherwise remain inaccessible. The vulnerability results in unauthorized data disclosure and enables traversal of internal boundaries, as the access scope is explicitly changed.

Affected Systems

Adobe ColdFusion, specifically any release prior to 2025.9 and 2023.20, remains impacted regardless of the underlying operating system. Any deployed instance that accepts network requests from potentially untrusted clients is considered vulnerable.

Risk and Exploitability

The CVSS score of 8.6 classifies the issue as high severity. No EPSS value is provided and the vulnerability is not listed in the CISA KEV catalog, yet the lack of user interaction and the changed scope imply a straightforward exploitation path once an attacker can issue arbitrary requests to the vulnerable server. The likely attack vector is remote, through network­exposed endpoints that accept input. Fast mitigation is essential to prevent data leakage.

Generated by OpenCVE AI on June 30, 2026 at 17:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the official Adobe ColdFusion update that eliminates the SSRF issue for the affected releases (2025.9, 2023.20 and earlier).
  • If a patch is not yet available, enforce a network‑level whitelist or reverse proxy to block outbound connections to untrusted hosts and restrict any service‑initiated external requests.
  • Reinforce application security by disabling or tightly configuring ColdFusion features that create outbound connections, and monitor server logs for anomalous external traffic.

Generated by OpenCVE AI on June 30, 2026 at 17:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 30 Jun 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe coldfusion
Vendors & Products Adobe
Adobe coldfusion

Tue, 30 Jun 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 16:00:00 +0000

Type Values Removed Values Added
Description ColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.
Title ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918)
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Adobe Coldfusion
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-06-30T16:45:19.575Z

Reserved: 2026-05-21T15:28:38.134Z

Link: CVE-2026-48285

cve-icon Vulnrichment

Updated: 2026-06-30T16:45:15.783Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-30T21:15:05Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)