Impact
The vulnerability allows an attacker to bypass the built‑in security controls of ColdFusion and obtain read and write privileges that are normally reserved for administrators. The issue is an authorization flaw that can be exploited without any user interaction, as the affected component is isolated to an administrative network zone by default. If successfully leveraged, the attacker could access protected data and modify application files, leading to a denial‑of‑service condition.
Affected Systems
Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are impacted. No specific patch‑level versions are listed, so all releases of these product lines are at risk until an update is applied.
Risk and Exploitability
The CVSS score of 9.6 places the vulnerability in the critical range, indicating high impact if exploited. The EPSS score of less than 1% suggests that exploitation is currently unlikely, though it does not rule out future attacks. The issue is not listed in the CISA KEV catalog, but the scope is changed, allowing the attacker to reach the entire application. The attack vector is inferred to be remote or internal on the administrative network, as the component is isolated by default and does not require user interaction.
OpenCVE Enrichment