Impact
ColdFusion suffers from an Incorrect Authorization flaw that allows an attacker to read and write data beyond their intended scope, effectively enabling privilege escalation. The vulnerability permits unauthorized access to confidential information and the ability to modify application data, potentially compromising the integrity and confidentiality of the system. This identified as CWE‑863, highlighting improper control of access permissions within the application.
Affected Systems
Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are impacted. No additional version detail is provided, but any installation of these product releases requires review for this flaw.
Risk and Exploitability
The CVSS score of 9.3 reflects a high severity, while the EPSS score indicates a very low, yet non‑zero, likelihood of exploitation. Based on the description, it is inferred that the likely attack vector is via unauthenticated web requests, since the issue does not require user interaction, and the scope is changed. The vulnerability can be exploited remotely by sending crafted HTTP requests to the ColdFusion server, allowing an attacker to gain unauthorized read and write access beyond their intended permissions. Though not listed in the CISA KEV catalog, the scope change make this vulnerability particularly concerning for systems exposed to network traffic.
OpenCVE Enrichment