Description
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-07-14
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an Incorrect Authorization flaw (CWE‑863) in Adobe ColdFusion that can lead to arbitrary code execution in the context of the current user.

Affected Systems

Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are potentially impacted. No specific affected product versions are listed in the CVE, so any release of these product lines is considered vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 9 indicates a high‑severity vulnerability, while the EPSS score being less than 1% shows that exploitation is currently considered low probability. Because the issue does not require user interaction and the scope is changed, the likely attack vector is a remote network attack, such as HTTP requests to the ColdFusion application that can trigger the flaw. Once exploited, the risk to the overall environment is high, although real‑world exploitation evidence appears limited. The vulnerability is not listed in CISA's KEV catalog.

Generated by OpenCVE AI on July 31, 2026 at 04:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest ColdFusion security patch released by Adobe for the affected versions, as outlined in the Adobe advisory.
  • Restart ColdFusion services after applying the patch to ensure the authorization corrections take effect.
  • Until a patch is applied, limit exposure access to ColdFusion administrative interfaces or restricting network access to the ColdFusion ports.

Generated by OpenCVE AI on July 31, 2026 at 04:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025
Vendors & Products Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Title ColdFusion | Incorrect Authorization (CWE-863)
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Coldfusion 2023 Coldfusion 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T10:33:15.972Z

Reserved: 2026-05-21T15:28:38.138Z

Link: CVE-2026-48327

cve-icon Vulnrichment

Updated: 2026-07-15T10:33:11.361Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T04:45:17Z

Weaknesses