Executive brief
Adobe ColdFusion, a platform for developing and deploying web applications, is affected by a security vulnerability that allows unauthorized access to internal resources. An attacker can exploit this flaw to bypass security protections and read sensitive information without needing any user interaction. This could lead to the exposure of internal data or configuration details that are normally protected from the public internet.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability (CWE-918) exists in Adobe ColdFusion versions 2025.9, 2023.20, and earlier. The flaw allows a remote, unauthenticated attacker to send crafted requests from the vulnerable server to internal or external resources. Because the 'Scope' is changed (S:C), the attacker can pivot from the ColdFusion application to access other services or metadata within the hosting environment that are not intended to be publicly accessible. This results in a high impact on confidentiality as the attacker can gain unauthorized read access to sensitive data. No user interaction is required for exploitation.
Affected products
- Adobe ColdFusion 2025.9, 2023.20 and earlier
Timeline
- 2026-06-30: disclosed
- 2026-06-30: advisory