Adobe ColdFusion Improper Input Validation Vulnerability Leading to Arbitrary Code Execution

Vulnerability

A vulnerability allowing arbitrary code execution has been identified in Adobe ColdFusion versions 2025.1, 2023.13, and 2021.19 and earlier. This issue arises from improper input validation, which could enable a high-privileged attacker to bypass security mechanisms and execute code in the context of the current user. Notably, exploitation of this vulnerability does not require user interaction, and it alters the scope of the attack.

Impact

Successful exploitation allows for arbitrary code execution in the context of the current user.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
10.0
exploitability
5.0
remediation
0.0
relevance
0.0
threat
0.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.