Impact
ColdFusion suffers from an insufficient enforcement of session expiration, enabling a high‑privileged attacker to bypass built‑in security controls and gain unauthorized write access. The flaw, classified as CWE‑613, does not require user interaction and can be exploited to write data outside the intended permissions.
Affected Systems
Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are affected. No specific patch versions are listed in the advisory until an update is applied.
Risk and Exploitability
The CVSS score of 2.7 marks this issue as low severity, and the EPSS score of less than 1 % indicates a very small probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation does not require user interaction and requires the attacker to have high‑privilege access to the application. Because of the low exploitation likelihood, the overall risk is considered low but patching is recommended.
OpenCVE Enrichment