Executive brief
Adobe ColdFusion, a platform for building and deploying web applications, is affected by a security flaw that allows unauthorized access to information. An attacker with low-level access to the system can bypass built-in security protections to read sensitive data they should not be able to see. This could lead to the exposure of internal configuration details or customer information, potentially impacting business operations and data privacy.
Technical details
Adobe ColdFusion (versions 2023 and 2025) contains an improper input validation vulnerability (CWE-20) within its core processing logic. This flaw allows a remote attacker with low-privileged credentials to bypass security feature constraints. Because the vulnerability results in a 'Scope Change' (S:C) in the CVSS metric, the impact extends beyond the immediate ColdFusion environment, potentially allowing unauthorized read access to sensitive data in related components. The attack is network-based, requires no user interaction, and has been addressed in ColdFusion 2023 Update 22 and ColdFusion 2025 Update 11.
Affected products
- Adobe ColdFusion 2025 <= 10
- Adobe ColdFusion 2023 <= 21
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory