HIGH
CVE-2023-26360
CVSS
8.6
KEV
Description
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.
Summary dbcve.org
Adobe ColdFusion 2018 (up to Update 15) and 2021 (up to Update 5) contain an Improper Access Control vulnerability that allows unauthenticated attackers to execute arbitrary code in the context of the current user without any user interaction.
Mitigation
Apply the vendor patches (ColdFusion 2018 Update 16+ and ColdFusion 2021 Update 6+) to remediate this improper access control vulnerability.
Weakness (CWE)
CWE-284
Improper Access Control
EPSS Score
97.34%
Probability of exploitation in next 30 days
99.9th percentile
References
http://packetstormsecurity.com/files/172079/Adobe-ColdFusion-Unauthenticated-Remote-Code-Execution.html
Exploit, Third Party Advisory, VDB Entry
https://helpx.adobe.com/security/products/coldfusion/apsb23-25.html
Patch, Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-26360
Third Party Advisory, US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.