Impact
The flaw is an improper control of code generation that allows attackers to inject and execute arbitrary code on the ColdFusion server. The CVE description explicitly states that the injected code runs in the context of the current user and that exploitation does not require user interaction. The advisory notes that the scope is changed, but it does not provide details on the resulting privilege level; it is inferred that a scope change could enable an attacker to gain higher privileges, but this inference is not directly stated in the input.
Affected Systems
Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are the impacted products. No specific patched versions are listed in the CNA data, so any installation of these releases should be reviewed for the vulnerability.
Risk and Exploitability
With a CVSS score of 9.6 the vulnerability is rated as critical, and the EPSS score of less than 1% indicates that exploitation attempts are currently rare. The flaw is not listed in CISA’s KEV catalog. Attackers can exploit the issue remotely by sending specially crafted content to the ColdFusion instance, triggering code execution without user interaction. The noted scope change suggests the possibility of privilege escalation, but this is an inferred consequence rather than a directly stated fact.
OpenCVE Enrichment