Impact
ColdFusion suffers from a Missing Authentication for Critical Function vulnerability classified as CWE‑306. This flaw allows an attacker to execute arbitrary code in the context of the user running the application. The vulnerability can be exploited without any user interaction, and the impact scope is elevated, meaning that exploitation on one system can potentially affect other components within the same environment.
Affected Systems
Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are listed as affected. No specific version ranges are provided in the CVE data, so any installation of these product lines that has not applied the latest security update is potentially vulnerable.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity, while the EPSS score of less than 1 % suggests a low likelihood of widespread exploitation at present. The vulnerability is not catalogued in CISA’s KEV list. Based on the description that exploitation does not require user interaction, the likely attack vector is remote access to a critical function that lacks proper authentication. This inference underscores the need for urgent remediation.
OpenCVE Enrichment