Impact
This vulnerability is an Incorrect Authorization flaw (CWE‑863) in Adobe ColdFusion that can lead to arbitrary code execution in the context of the current user.
Affected Systems
Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are potentially impacted. No specific affected product versions are listed in the CVE, so any release of these product lines is considered vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 9 indicates a high‑severity vulnerability, while the EPSS score being less than 1% shows that exploitation is currently considered low probability. Because the issue does not require user interaction and the scope is changed, the likely attack vector is a remote network attack, such as HTTP requests to the ColdFusion application that can trigger the flaw. Once exploited, the risk to the overall environment is high, although real‑world exploitation evidence appears limited. The vulnerability is not listed in CISA's KEV catalog.
OpenCVE Enrichment