PT-2025-50284 · Adobe · Coldfusion

Published

2025-12-09

·

Updated

2025-12-16

·

CVE-2025-61811

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ColdFusion versions 2025.4, 2023.16, and 2021.22 and earlier
Description An improper access control issue exists in ColdFusion that could allow for arbitrary code execution with the privileges of the current user. An attacker with high privileges could bypass security measures and execute malicious code. Exploitation of this issue does not require user interaction. The scope of the issue is changed.
Recommendations Update ColdFusion to a version later than 2021.22. Update ColdFusion to a version later than 2023.16. Update ColdFusion to a version later than 2025.4.

Fix

Improper Access Control

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2025-15516
CVE-2025-61811

Affected Products

Coldfusion