Impact
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory vulnerability that permits reading arbitrary files outside the intended directory. The flaw can expose sensitive data and log files and does not require user interaction, meaning an attacker can trigger it remotely. The CVSS base score of 6.8 indicates a moderate severity with scope changed, giving the attacker the ability to affect the entire system.
Affected Systems
The vulnerability applies to Adobe ColdFusion 2023 and Adobe ColdFusion 2025 releases. Any installation of these products that has not yet applied the vendor’s patch is at risk.
Risk and Exploitability
With a CVSS score of 6.8 the risk is moderate but still critical for protecting data confidentiality. The EPSS score of less than 1% shows a low the vulnerability is not currently listed in CISA KEV. Likely attack vectors are remote over the web interface, as the flaw is triggered by crafted URLs or requests that contain path traversal sequences. However, the official description does not specify the exact network surface, so the assessment infers a typical HTTP‑based exploitation path.
OpenCVE Enrichment