HIGH

CVE-2023-26360

Adobe Coldfusion 2023-03-23 CVSS v3.1
CVSS
8.6
KEV

Description

Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.

Summary dbcve.org

Adobe ColdFusion 2018 (up to Update 15) and 2021 (up to Update 5) contain an Improper Access Control vulnerability that allows unauthenticated attackers to execute arbitrary code in the context of the current user without any user interaction.

Mitigation

Apply the vendor patches (ColdFusion 2018 Update 16+ and ColdFusion 2021 Update 6+) to remediate this improper access control vulnerability.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-284 Improper Access Control

EPSS Score

97.34%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE