Impact
ColdFusion versions 2025.9, 2023.20, and earlier contain a path traversal flaw (CWE‑22) that can give an attacker the ability to read any file on the file system set of files. This weakness could be used to expose confidential configuration data, alter application logic, or undermine the integrity of the system. The flaw is classified as an improper limitation of a pathname to a restricted directory, and the CVSS score of 9.3 indicates a severe impact to the ColdFusion application is sufficient to trigger the flaw.
Affected Systems
The affected products are Adobe ColdFusion, specifically releases 2025.9, 2023.20 and earlier versions that have not been updated to a fixed release.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.3, and its EPSS score of 2% indicates a very small but non‑zero likelihood of exploitation, yet the lack of user interaction and the remote nature of the attack mean that exploitation can occur over the Web with minimal effort. The issue is not listed in CISA's KEV catalog, but the scope change indicates that components beyond the originating context can be affected, raising the overall risk. The likely attack vector, based on inferential analysis, is that an attacker supplies a specially crafted path in a ColdFusion request to read or write unauthorized files.
OpenCVE Enrichment