CVE-2026-25652

Summary

is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain unauthorized read and write access. Exploitation of this issue does not require user interaction.

Affected Software

VendorProductVersion RangeStatus
AdobeColdFusion 20250 <= 2025.0.11affected
AdobeColdFusion 20252025.0.12unaffected
AdobeColdFusion 20230 <= 2023.0.22affected
AdobeColdFusion 20232023.0.23unaffected

Weaknesses

  • CWE-863: Incorrect Authorization (CWE-863)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References