Impact
An uncontrolled search path element flaw (CWE‑427) exists in Adobe ColdFusion versions 2025.9, 2023.20 and earlier. The vulnerability allows a malicious file to be loaded when a user opens it, leading to the execution of arbitrary code with the privileges of the account running ColdFusion. The flaw is marked as a scope‑changing issue, meaning that the attack can affect higher‑privileged processes beyond the original context.
Affected Systems
Adobe ColdFusion servers running any version up to and including 2025.9, 2023.20, and earlier releases. The issue is not limited to a specific module but applies to the core ColdFusion runtime.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity level, and the EPSS score of <1% indicates a very low but measurable exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires user interaction: a victim must open a malicious file. Because the flaw has a scope change, the impact is elevated, but the attack must be initiated by the end‑user, limiting the attack surface. Nonetheless, any entity that receives malicious files through ColdFusion remains at high risk.
OpenCVE Enrichment