CVE-2023-26360

Published Mar 23, 2023

Last updated 4 months ago

Analyzed

Description

Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.

Risk scores

CVSS 3.1

Primary
8.6
4
3.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
HIGH

Known exploits

Data from CISA

Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

Mar 15, 2023

Apr 5, 2023

Apply updates per vendor instructions.

Weaknesses

NVD-CWE-Other
CWE-284

Source

psirt@adobe.com

Configurations