Improper Authentication in ColdFusion by Adobe
CVE-2025-30287
8.2HIGH
What is CVE-2025-30287?
ColdFusion versions 2023.12, 2021.18, and 2025.0 and earlier are impacted by an improper authentication vulnerability that permits arbitrary code execution within the context of an authenticated user. This security issue enables attackers to bypass existing authentication controls. Successful exploitation requires the targeted user to be manipulated into executing malicious actions within the application, effectively granting the attacker access to the same permissions as the compromised user.
Affected Version(s)
ColdFusion 0 <= 2025.0