Impact
The vulnerability is an improper input validation flaw that permits arbitrary code execution in the context of the current user. The likely attack vector is a remote crafted request; based on the description, it is inferred that attackers can trigger it without any user interaction, leading to compromise of the system. The weakness is due to insufficient input checks.
Affected Systems
Adobe ColdFusion versions 2025.9, 2023.20, and all earlier releases are affected. Any server running these releases is vulnerable until a fix is applied or the application is removed.
Risk and Exploitability
The CVSS score of 10 indicates an extremely severe vulnerability. The EPSS score of 2% indicates a low but non-negligible likelihood of exploitation, and the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the attack vector is remote and requires no user interaction; exploitation can be triggered by sending crafted input, making this a highly dangerous threat.
OpenCVE Enrichment