Description
ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-07-14
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

ColdFusion suffers from a Missing Authentication for Critical Function vulnerability classified as CWE‑306. This flaw allows an attacker to execute arbitrary code in the context of the user running the application. The vulnerability can be exploited without any user interaction, and the impact scope is elevated, meaning that exploitation on one system can potentially affect other components within the same environment.

Affected Systems

Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are listed as affected. No specific version ranges are provided in the CVE data, so any installation of these product lines that has not applied the latest security update is potentially vulnerable.

Risk and Exploitability

The CVSS score of 9.3 indicates critical severity, while the EPSS score of less than 1 % suggests a low likelihood of widespread exploitation at present. The vulnerability is not catalogued in CISA’s KEV list. Based on the description that exploitation does not require user interaction, the likely attack vector is remote access to a critical function that lacks proper authentication. This inference underscores the need for urgent remediation.

Generated by OpenCVE AI on July 31, 2026 at 04:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Adobe patch referenced in the APSB26‑82 bulletin immediately.
  • Disable or isolate the exposed ColdFusion functions that lack proper authentication until the patch is applied.
  • Enforce strict authentication and authorization on all exposed functions.
  • Monitor ColdFusion logs for anomalous access attempts and block suspicious activity.

Generated by OpenCVE AI on July 31, 2026 at 04:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025
Vendors & Products Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Title ColdFusion | Missing Authentication for Critical Function (CWE-306)
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Adobe Coldfusion 2023 Coldfusion 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T10:33:56.694Z

Reserved: 2026-05-21T15:28:38.137Z

Link: CVE-2026-48325

cve-icon Vulnrichment

Updated: 2026-07-15T10:33:52.144Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T05:00:05Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function