Executive brief
Adobe ColdFusion, a platform for building and deploying web applications, contains a security flaw where user sessions do not expire correctly. This could allow a high-privileged user to bypass certain security features and perform unauthorized changes to the system. While the risk is limited to users who already have significant access, it could lead to unauthorized data modification or configuration changes.
Technical details
Adobe ColdFusion is vulnerable to insufficient session expiration (CWE-613). The flaw allows a high-privileged attacker to bypass security features because sessions remain valid longer than intended. This vulnerability can be exploited over the network without user interaction, potentially leading to unauthorized write access or modification of system data. The issue affects ColdFusion 2025 (versions 10 and below) and ColdFusion 2023 (versions 21 and below). Adobe has released updates to address this vulnerability in ColdFusion 2025 Update 11 and ColdFusion 2023 Update 22.
Affected products
- Adobe ColdFusion 2025 <= 10
- Adobe ColdFusion 2023 <= 21
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory