Executive brief
Adobe ColdFusion, a platform for building web applications, is affected by a vulnerability that allows an authorized user to slow down or crash the application. By consuming excessive system resources, a high-privileged attacker can cause a denial-of-service, impacting the availability of the service for other users. This issue does not require any interaction from other users to be exploited.
Technical details
Adobe ColdFusion is vulnerable to uncontrolled resource consumption (CWE-400) in versions 2023.18, 2025.6 and earlier. The vulnerability allows a high-privileged attacker with adjacent network access to exhaust system resources without any user interaction. This can lead to a partial denial-of-service (DoS) by significantly reducing application performance or causing it to become unresponsive. The CVSS score is low (2.4) primarily because the attack requires high privileges and is limited to the adjacent network. Adobe has released security updates to address this issue in advisory APSB26-38.
Affected products
- Adobe ColdFusion 2023.18, 2025.6 and earlier
Timeline
- 2026-04-14: disclosed
- 2026-04-14: advisory: Adobe published APSB26-38