Impact
ColdFusion is vulnerable to an improper input validation flaw that permits a low‑privileged attacker to bypass a core security feature, enabling unauthorized read access to protected resources. The flaw alters the application scope and does not require user interaction, making it potentially exploitable from any environment with network connectivity to the affected server. The weakness is classified as CWE‑20.
Affected Systems
All installations of Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are vulnerable, as the vendor lists the two product lines without specifying version ranges. Until Adobe releases a patch or a newer version that incorporates the fix, every installation in these lines is considered vulnerable.
Risk and Exploitability
The CVSS score of 7.7 marks the issue as high severity, yet the EPSS score of less than 1% indicates a very low probability of real‑world exploitation. The vulnerability is not present in CISA’s KEV catalog. The lack of a user‑interaction requirement and the description’s implication of remote reachability suggest that the attack vector is likely network‑based access to the ColdFusion service, which can be exploited by attackers with external network exposure.
OpenCVE Enrichment