Impact
ColdFusion is affected by an Incorrect Authorization vulnerability that allows privilege escalation, enabling an attacker to gain unauthorized read and write access. The vulnerable component is restricted to an administrative network zone by default, yet exploitation does not require user interaction and changes scope, providing the attacker with access beyond intended permissions. This improper access control flaw is identified as CWE-863.
Affected Systems
Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are impacted. No additional version detail is provided, but any installation of these product releases requires review for this flaw.
Risk and Exploitability
The CVSS score of 9.3 reflects a high severity, while the EPSS score indicates a very low, yet non-zero, likelihood of exploitation. Based on the description, it is inferred that the likely attack vector is via unauthenticated web requests, since the issue does not require user interaction, and the scope is changed. The vulnerability can be exploited remotely by sending crafted HTTP requests to the ColdFusion server, allowing an attacker to gain unauthorized read and write access beyond their intended permissions. Though not listed in the CISA KEV catalog, the scope change make this vulnerability particularly concerning for systems exposed to network traffic.
OpenCVE Enrichment