Impact
The flaw is an incorrect authorization vulnerability in Adobe ColdFusion that allows an attacker to bypass internal security controls, resulting in limited unauthorized read and write access to protected data. This can in turn cause a limited disruption to availability of the affected application. The weakness is categorized as CWE‑863.
Affected Systems
Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are affected by this issue; the CVE does not specify a narrower set of versions within those releases.
Risk and Exploitability
The CVSS score of 7.3 indicates high severity. The EPSS score of less than 1 % suggests that exploitation is currently considered unlikely in the wild, and the flaw is not listed in the CISA KEV catalog. Exploitation does not require user interaction; the likely attack vector is remote access to a ColdFusion instance that is reachable from the network, enabling an attacker to leverage the incorrect authorization logic to obtain read/write privileges.
OpenCVE Enrichment