Improper Authentication in ColdFusion by Adobe
CVE-2025-30287
7.8HIGH
Summary
ColdFusion versions 2023.12, 2021.18, and 2025.0 and earlier are impacted by an improper authentication vulnerability that permits arbitrary code execution within the context of an authenticated user. This security issue enables attackers to bypass existing authentication controls. Successful exploitation requires the targeted user to be manipulated into executing malicious actions within the application, effectively granting the attacker access to the same permissions as the compromised user.
Affected Version(s)
ColdFusion 0 <= 2025.0
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved