CVE-2026-71387

8.8

Adobe · ColdFusion

An incorrect authorization vulnerability in Adobe ColdFusion could allow an attacker to execute arbitrary code in the context of the current user.

Executive summary

Adobe ColdFusion suffers from an incorrect authorization flaw that may enable an attacker to perform unauthorized actions or execute code in the context of the current user session.

Vulnerability

This is an incorrect authorization vulnerability where the application fails to properly validate user permissions. This allows an attacker on an adjacent network to potentially bypass security controls and execute arbitrary code.

Business impact

The ability to bypass authorization mechanisms represents a significant security failure, as it allows attackers to operate with the permissions of the current user. Given the CVSS score of 8.8, this vulnerability poses a high risk of unauthorized system access, data compromise, and potential full system takeover if the affected user holds elevated privileges.

Remediation

Immediate Action: Apply the vendor-supplied security patches, upgrading ColdFusion to version 2025.0.12 or 2023.0.23.

Proactive Monitoring: Monitor application access logs for unauthorized access attempts or unusual patterns in administrative function calls.

Compensating Controls: Restrict network access to the ColdFusion server to trusted IP addresses and enforce strict access control lists to mitigate potential lateral movement.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Addressing this incorrect authorization vulnerability is critical to maintaining the security posture of the application. Administrators should deploy the identified patches as soon as possible to ensure that authorization controls are correctly enforced and to minimize the risk of unauthorized code execution.

More Adobe CVEs