Description
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-07-14
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

ColdFusion suffers from an Incorrect Authorization flaw that allows an attacker to read and write data beyond their intended scope, effectively enabling privilege escalation. The vulnerability permits unauthorized access to confidential information and the ability to modify application data, potentially compromising the integrity and confidentiality of the system. This identified as CWE‑863, highlighting improper control of access permissions within the application.

Affected Systems

Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are impacted. No additional version detail is provided, but any installation of these product releases requires review for this flaw.

Risk and Exploitability

The CVSS score of 9.3 reflects a high severity, while the EPSS score indicates a very low, yet non‑zero, likelihood of exploitation. Based on the description, it is inferred that the likely attack vector is via unauthenticated web requests, since the issue does not require user interaction, and the scope is changed. The vulnerability can be exploited remotely by sending crafted HTTP requests to the ColdFusion server, allowing an attacker to gain unauthorized read and write access beyond their intended permissions. Though not listed in the CISA KEV catalog, the scope change make this vulnerability particularly concerning for systems exposed to network traffic.

Generated by OpenCVE AI on July 31, 2026 at 04:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe ColdFusion security update (APSB26‑82) that addresses the incorrect authorization issue, or upgrade to a newer release that contains the fix.
  • If an update cannot be applied immediately, restrict external access to ColdFusion installations by placing them behind firewalls or network segmentation, allowing connections only from trusted internal networks.
  • Strengthen application‑level access control by reviewing and tightening role‑based permissions to ensure that users have only the minimum necessary read/write rights; audit and remove any excessive privileges that could be abused by this flaw.

Generated by OpenCVE AI on July 31, 2026 at 04:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025
Vendors & Products Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025

Thu, 16 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of this issue does not require user interaction. Scope is changed.
Title ColdFusion | Incorrect Authorization (CWE-863)
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Adobe Coldfusion 2023 Coldfusion 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-16T03:55:24.149Z

Reserved: 2026-05-21T15:28:38.137Z

Link: CVE-2026-48321

cve-icon Vulnrichment

Updated: 2026-07-15T14:24:58.553Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T04:45:17Z

Weaknesses