Improper Access Control Vulnerability in ColdFusion by Adobe
CVE-2026-75998

7.5HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
8 September 2026

What is CVE-2026-75998?

Adobe ColdFusion is impacted by an improper access control vulnerability that enables attackers to perform arbitrary file system reads. This security issue allows unauthorized access to sensitive files and directories, reaching beyond the limits of normal access permissions. Notably, the exploitation of this vulnerability does not necessitate any user interaction, heightening the risk of unauthorized data exposure.

Affected Version(s)

ColdFusion 2023 0 <= 23

ColdFusion 2025 0 <= 12

ColdFusion 2023 24

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.