CVE-2026-83961
largePrivilege Escalation via Improper Authentication in Adobe ColdFusion
CVE-2026-83961 is an improper authentication (CWE-287) flaw in Adobe ColdFusion that allows an unauthenticated attacker to achieve privilege escalation. The vulnerable component sits in an administrative network zone by default, and the CVSS vector (AV:A) indicates an attacker needs access to an adjacent network; no user interaction is required to trigger the flaw. Successful exploitation grants limited read and write access, and the changed scope means the impact extends beyond the vulnerable component's own security scope. Any organization running Adobe ColdFusion on affected versions is impacted until patched, with the highest risk in deployments where the administrative zone is reachable from broader or adjacent networks. There is currently no known exploitation: no public proof-of-concept exists, the flaw is not in CISA KEV, and EPSS is low at 0.2%.
What to do: Apply the patched ColdFusion release referenced in Adobe's security bulletin as soon as practical, since no workaround is confirmed. In the interim, strictly firewall the administrative network zone hosting the vulnerable component so it is not reachable from user or adjacent network segments. Review whether any admin-zone interface is exposed beyond its intended zone and monitor ColdFusion logs for unexpected read/write activity.
| adobe coldfusion | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
ColdFusion is affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain limited read and write access. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.
- Vendors
- adobe
- Products
- coldfusion
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.