Impact
The vulnerability is an improper input validation flaw that permits arbitrary code execution in the context of the current user. Attackers can trigger it without any user interaction, and the system compromise. The weakness is insufficient input checks.
Affected Systems
Adobe ColdFusion versions 2025.9, 2023.20 and all earlier releases are affected. Any server running these releases is vulnerable until a fix is applied or the application removed.
Risk and Exploitability
The CVSS score of 10 indicates an extremely severe vulnerability. The EPSS score of 2% indicates a low but non-negligible likelihood of exploitation. The vulnerability is not listed in CISA KEV, yet the lack of such a listing does not mitigate the risk. Based on the description, the flaw can be triggered by sending crafted input without any user interaction, making it a highly dangerous threat.
OpenCVE Enrichment