Executive brief
Adobe ColdFusion, a platform for building and deploying web applications, is affected by a security vulnerability that allows attackers to bypass internal security controls. By exploiting this flaw, an attacker with low-level access can force the server to perform unauthorized requests, potentially leading to the exposure of sensitive internal data. This could result in the theft of confidential information or provide a foothold for further attacks within the corporate network.
Technical details
Adobe ColdFusion (versions 2023 and 2025) contains a Server-Side Request Forgery (SSRF) vulnerability, classified as CWE-918. The flaw allows a low-privileged attacker to send crafted requests from the vulnerable server, effectively bypassing security features such as firewalls or access control lists that protect internal resources. The vulnerability has a changed scope (S:C), meaning the impact extends beyond the ColdFusion environment to other systems reachable by the server. Exploitation requires network access and low-level authentication but does not require user interaction. Adobe has released patches (APSB26-82) to address this issue in ColdFusion 2023 Update 22 and ColdFusion 2025 Update 11.
Affected products
- Adobe ColdFusion 2025 <= 10
- Adobe ColdFusion 2023 <= 21
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory