ZeroHour

CVE-2026-83961

large

Privilege Escalation via Improper Authentication in Adobe ColdFusion

CVSS 3.1
7.1 high
EPSS
<1%p13
Published
()
Modified
AI analysis

CVE-2026-83961 is an improper authentication (CWE-287) flaw in Adobe ColdFusion that allows an unauthenticated attacker to achieve privilege escalation. The vulnerable component sits in an administrative network zone by default, and the CVSS vector (AV:A) indicates an attacker needs access to an adjacent network; no user interaction is required to trigger the flaw. Successful exploitation grants limited read and write access, and the changed scope means the impact extends beyond the vulnerable component's own security scope. Any organization running Adobe ColdFusion on affected versions is impacted until patched, with the highest risk in deployments where the administrative zone is reachable from broader or adjacent networks. There is currently no known exploitation: no public proof-of-concept exists, the flaw is not in CISA KEV, and EPSS is low at 0.2%.

What to do: Apply the patched ColdFusion release referenced in Adobe's security bulletin as soon as practical, since no workaround is confirmed. In the interim, strictly firewall the administrative network zone hosting the vulnerable component so it is not reachable from user or adjacent network segments. Review whether any admin-zone interface is exposed beyond its intended zone and monitor ColdFusion logs for unexpected read/write activity.

Affected
adobe coldfusion
Estimated exposure
largetens of thousands of ColdFusion deployments (roughly 30k–50k internet-exposed ColdFusion servers), with only admin-zone-reachable instances directly exploitable — Public internet-wide scan data consistently places the installed base of ColdFusion servers in the tens of thousands, and the component's default restriction to an administrative network zone (plus the adjacent-network attack requirement)…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

ColdFusion is affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain limited read and write access. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.

Vendors
adobe
Products
coldfusion
Weakness
CWE-287
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.