Incorrect Authorization in Adobe ColdFusion Enables Security Bypass
CVSS 3.1
9.6critical
EPSS
<1%p32
Published
()
Modified
AI analysis
Adobe ColdFusion contains an incorrect authorization flaw (CWE-863) that permits a security feature bypass, rated critical at CVSS 9.6. An attacker with access to the adjacent network — the vulnerable component sits in the administrative network zone by default — can trigger it with no privileges and no user interaction. Because the scope is 'changed,' the flaw lets the attacker cross a trust boundary, bypass security controls, and gain unauthorized read and write access, potentially causing an application denial-of-service. Any organization running an affected ColdFusion release is exposed, but default configurations that confine the component to the admin network zone limit how many are remotely reachable; the provided data did not specify affected version ranges. Exploitation status is currently quiet: no public proof-of-concept, not listed in CISA KEV, and EPSS estimates only a ~0.4% probability of exploitation within 30 days, though Adobe has shipped fixes as part of a recent ColdFusion patch release.
What to do: Apply Adobe's latest ColdFusion security update as soon as practical and check Adobe's bulletin for the specific affected versions, which were not included in this feed. Until patched, verify the vulnerable component is actually confined to the administrative network zone and enforce firewall/ACL rules so untrusted users on the adjacent network cannot reach it. Also confirm no ColdFusion administrative interfaces are exposed outside the admin zone and review logs for unexplained administrative-zone access or anomalous write activity.
Affected
Adobe ColdFusion
—
Estimated exposure
largetens of thousands of ColdFusion installations (est.), with directly exploitable instances likely fewer because the vulnerable component is admin-zone… — Public internet scans historically show tens of thousands of Adobe ColdFusion servers exposed online and ColdFusion remains widely deployed in enterprises, but the default administrative network zone restriction means only deployments that…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, potentially resulting in an application denial-of-service condition. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.
Adobe patches seven flaws in ColdFusion, Commerce, and Campaign Classic, including actively exploited CVE-2026-71362 enabling customer account takeover.
Adobe issued Priority 1 updates fixing CVSS 10.0 flaws in ColdFusion (CVE-2026-48362, OS command injection) and Campaign Classic (CVE-2026-71398, CVE-2026-27302, incorrect authorization), plus CVE-2026-71362 (CVSS 9.1) in Adobe Commerce and Magento Open Source. Sansec reports threat actors are actively exploiting CVE-2026-71362 to switch customer sessions to other accounts and access private customer data. Adobe-hosted Campaign Classic instances are already remediated, while on-premise deployments are urged to patch within 72 hours. ColdFusion fixes ship in versions 2025.0.12 and 2023.0.23, and Campaign Classic fixes in v7 7.4.4 build 9400.