Adobe ColdFusion authorization bypass — CVSS 9.3
Authorization bypass in Adobe ColdFusion allows an unauthenticated attacker to bypass access controls. Patched in ColdFusion 2025 Update 11 and 2023 Update 22.
- Vendor
- Adobe
- Product
- ColdFusion 2023, ColdFusion 2025
- CVSS
- 9.3
- EPSS (exploit probability)
- 0.5%
- Status
- patched
- Published
Adobe ColdFusion contains an authorization bypass vulnerability that allows an unauthenticated remote attacker to circumvent access controls and reach protected functionality. Patched as part of Adobe’s July 2026 ColdFusion security update alongside seven other critical CVEs in the same product.
Apply ColdFusion 2025 Update 11 or ColdFusion 2023 Update 22. Authorization bypasses in server-side platforms with a KEV history like ColdFusion warrant immediate patching on any internet-exposed installation.
Source: NVD · Adobe Security Bulletin
