Impact
ColdFusion is affected by an Incorrect Authorization vulnerability that allows a low-privileged attacker to cause the application to crash, resulting in a denial-of-service condition. The flaw is categorized as CWE-863 and does not require user interaction. If exploited, the attacker can repeatedly terminate the ColdFusion service, disrupting legitimate application functionality and potentially impacting overall system availability.
Affected Systems
Adobe ColdFusion 2023 and Adobe ColdFusion 2025 products are impacted. No specific version numbers are provided, so all releases prior to an unspecified update may be vulnerable. Security administrators should review their installed ColdFusion version against Adobe’s advisory to ensure any affected instances are patched.
Risk and Exploitability
With a CVSS score of 6.5 the vulnerability is considered moderate. The EPSS score of less than 1% indicates a low probability of exploitation in the wild, and the issue is not listed in CISA’s KEV catalog. Attackers require only low privileges and no user interaction, suggesting that the vulnerability could be abused remotely by anyone who can reach the affected application. Because the impact is limited to service availability, the overall threat is moderate but still warrants timely remediation.
OpenCVE Enrichment