Executive brief
Adobe ColdFusion, a platform for building and deploying web applications, is affected by a security flaw that could allow an attacker to take full control of the server. A high-privileged user on the local network could bypass security checks to run unauthorized commands or access sensitive session data. This could lead to a complete compromise of the application and the data it manages without any interaction from other users.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in Adobe ColdFusion versions 2023.19, 2025.8, and earlier. The flaw allows a high-privileged attacker with adjacent network access to bypass authorization logic and execute arbitrary code in the context of the current user. Because the vulnerability results in a scope change (S:C), an exploit can impact components beyond the immediate security scope of the ColdFusion environment. No user interaction is required for successful exploitation. Adobe has addressed this issue in security bulletin APSB26-64.
Affected products
- Adobe ColdFusion 2023 2023.19 and earlier
- Adobe ColdFusion 2025 2025.8 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory: Adobe security bulletin APSB26-64 published