Impact
Adobe ColdFusion versions 2023 and 2025 contain an Incorrect Authorization flaw that allows an attacker to run arbitrary code in the context of the user who is logged into the system. The vulnerability stems from insufficient enforcement of access controls on a privileged operation, enabling an attacker to bypass normal authentication checks and execute code without requiring user interaction. If exploited, the attacker gains the privileges of the current user, potentially leading to full system compromise.
Affected Systems
The flaw is limited to ColdFusion 2023 and ColdFusion 2025. By default, the vulnerable component is accessible only within an administrative network zone, but the lack of proper authorization checks means that any entity with network access to that zone could potentially exploit the issue. No specific client or operating system variants are mentioned, so the impact applies globally to the affected ColdFusion releases.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity, while the EPSS score of less than 1% suggests that exploitation is currently unlikely in the broader threat landscape. Because the vulnerability does not require user interaction and is confined to a network zone, attackers who already have network reach can potentially exploit it; however, the lack of a public exploit and minimal exploitation probability reduce immediate risk. The issue is not listed in the CISA KEV catalog, but its high CVSS score and the potential for remote code execution warrant swift remediation.
OpenCVE Enrichment