Impact
This vulnerability arises from Adobe ColdFusion’s improper neutralization of directives in dynamically evaluated code, known as eval injection. An attacker can exploit this weakness to execute arbitrary code without requiring user interaction. The flaw can change the scope of execution, allowing the attacker to gain the privileges of the current user, potentially compromising the entire application and underlying infrastructure.
Affected Systems
Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are affected. The vulnerability applies to all deployments of these versions, regardless of configuration, because the eval functionality is present in core components.
Risk and Exploitability
The risk is high, with a CVSS score of 8.6 and no evidence the EPSS score is publicly available. The vulnerability is not listed in CISA’s KEV catalog, yet the lack of user interaction and scope change increase the likelihood of exploitation. Attackers could trigger the flaw by sending specially crafted requests that include undelimited directives to be evaluated, enabling remote code execution.
OpenCVE Enrichment