Description
ColdFusion is affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain limited read and write access. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-09-03
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

ColdFusion suffers from an Improper Authentication flaw that can allow an attacker to attain limited read and write capabilities, effectively elevating privileges within the application. The vulnerability resides solely in the administrative network zone by default and does not require any user interaction. Because the flaw changes scope, access that would normally be restricted can be bypassed once authenticated.

Affected Systems

Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are the affected product families. No other products or versions are listed as vulnerable.

Risk and Exploitability

The CVSS score of 7.1 marks the issue as medium‑to‑high severity, while the EPSS score is not available, leaving the exact likelihood of exploitation uncertain. The vulnerability is not listed in the CISA KEV catalog, indicating that no widely publicly known exploits have been documented. An attacker can target the isolated administrative zone, which if not adequately protected, could be compromised to gain restricted read/write access and potentially expand privileges system‑wide.

Generated by OpenCVE AI on September 3, 2026 at 16:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available Adobe ColdFusion patches or updates from the official Adobe security advisory.
  • Restrict access to the ColdFusion administrative zone by implementing firewall rules or VPN only access.
  • Enforce strong authentication policies, such as complex passwords and two‑factor authentication, and disable unsupported authentication methods.

Generated by OpenCVE AI on September 3, 2026 at 16:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025
Vendors & Products Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025

Thu, 03 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description ColdFusion is affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain limited read and write access. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.
Title ColdFusion | Improper Authentication (CWE-287)
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L'}


Subscriptions

Adobe Coldfusion 2023 Coldfusion 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-03T16:09:37.752Z

Reserved: 2026-09-01T00:25:45.963Z

Link: CVE-2026-83961

cve-icon Vulnrichment

Updated: 2026-09-03T15:55:37.938Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-03T16:18:23.383

Modified: 2026-09-03T17:17:24.920

Link: CVE-2026-83961

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T16:30:05Z

Weaknesses