Improper Authentication in ColdFusion by Adobe
CVE-2025-30287

7.8HIGH

Key Information:

Vendor
Adobe
Vendor
CVE Published:
8 April 2025

Summary

ColdFusion versions 2023.12, 2021.18, and 2025.0 and earlier are impacted by an improper authentication vulnerability that permits arbitrary code execution within the context of an authenticated user. This security issue enables attackers to bypass existing authentication controls. Successful exploitation requires the targeted user to be manipulated into executing malicious actions within the application, effectively granting the attacker access to the same permissions as the compromised user.

Affected Version(s)

ColdFusion 0 <= 2025.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.