Impact
ColdFusion suffers from an Improper Authentication flaw that can allow an attacker to attain limited read and write capabilities, effectively elevating privileges within the application. The vulnerability resides solely in the administrative network zone by default and does not require any user interaction. Because the flaw changes scope, access that would normally be restricted can be bypassed once authenticated.
Affected Systems
Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are the affected product families. No other products or versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 7.1 marks the issue as medium‑to‑high severity, while the EPSS score is not available, leaving the exact likelihood of exploitation uncertain. The vulnerability is not listed in the CISA KEV catalog, indicating that no widely publicly known exploits have been documented. An attacker can target the isolated administrative zone, which if not adequately protected, could be compromised to gain restricted read/write access and potentially expand privileges system‑wide.
OpenCVE Enrichment