AdobeCVE-2026-83961
Adobe ColdFusion: improper authentication
High7.1CVE-2026-83961 · Published Sep 3, 2026 · updated Sep 9, 2026
ColdFusion is affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain limited read and write access. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| ColdFusion 2023 Product | <= 2023.0.22 | No fix yet |
| ColdFusion 2025 Product | <= 2025.0.11 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-287
More Adobe advisories
All Adobe| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 8 | Adobe Commerce: cross-site scripting | Critical9.3 | No fix yet |
| Sep 8 | Adobe Photoshop Android: path traversal | Medium5.0 | No fix yet |
| Sep 8 | Adobe Photoshop Android: session fixation | High7.4 | No fix yet |
| Sep 8 | Adobe Animate: code injection | High8.2 | No fix yet |
| Sep 7 | Adobe Commerce: code execution | Critical10.0 | No fix yet |
| Sep 3 | Adobe Substance 3D Sampler: heap buffer overflow | High7.8 | No fix yet |