Description
ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.
Published: 2026-07-14
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

ColdFusion suffers from an insufficient enforcement of session expiration, enabling a high‑privileged attacker to bypass built‑in security controls and gain unauthorized write access. The flaw, classified as CWE‑613, does not require user interaction and can be exploited to write data outside the intended permissions.

Affected Systems

Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are affected. No specific patch versions are listed in the advisory until an update is applied.

Risk and Exploitability

The CVSS score of 2.7 marks this issue as low severity, and the EPSS score of less than 1 % indicates a very small probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation does not require user interaction and requires the attacker to have high‑privilege access to the application. Because of the low exploitation likelihood, the overall risk is considered low but patching is recommended.

Generated by OpenCVE AI on July 31, 2026 at 04:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest ColdFusion patch or upgrade to a version that includes the session expiration fix, as released by Adobe.
  • Configure strict session timeout settings to ensure inactive sessions expire automatically.
  • Limit write permissions to accounts that truly need them and monitor logs for anomalous write activity.

Generated by OpenCVE AI on July 31, 2026 at 04:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025
Vendors & Products Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025

Wed, 15 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.
Title ColdFusion | Insufficient Session Expiration (CWE-613)
Weaknesses CWE-613
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Adobe Coldfusion 2023 Coldfusion 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T14:36:31.234Z

Reserved: 2026-05-21T15:28:38.138Z

Link: CVE-2026-48329

cve-icon Vulnrichment

Updated: 2026-07-15T14:36:26.573Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T04:45:17Z

Weaknesses
  • CWE-613

    Insufficient Session Expiration