Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2023-26360

Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.

  • Published: Mar 23, 2023
  • Updated: Jun 29, 2024
  • CVE: CVE-2023-26360
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 8.6
  • AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Software From Fixed in
adobe / coldfusion 2018 2018.x
adobe / coldfusion 2018-update1 2018-update1.x
adobe / coldfusion 2018-update2 2018-update2.x
adobe / coldfusion 2018-update3 2018-update3.x
adobe / coldfusion 2018-update4 2018-update4.x
adobe / coldfusion 2018-update5 2018-update5.x
adobe / coldfusion 2018-update6 2018-update6.x
adobe / coldfusion 2018-update7 2018-update7.x
adobe / coldfusion 2018-update8 2018-update8.x
adobe / coldfusion 2018-update9 2018-update9.x
adobe / coldfusion 2018-update10 2018-update10.x
adobe / coldfusion 2021 2021.x
adobe / coldfusion 2021-update1 2021-update1.x
adobe / coldfusion 2021-update2 2021-update2.x
adobe / coldfusion 2021-update3 2021-update3.x
adobe / coldfusion 2018-update13 2018-update13.x
adobe / coldfusion 2018-update12 2018-update12.x
adobe / coldfusion 2018-update11 2018-update11.x
adobe / coldfusion 2021-update4 2021-update4.x
adobe / coldfusion 2018-update14 2018-update14.x
adobe / coldfusion 2021-update5 2021-update5.x
adobe / coldfusion 2018-update15 2018-update15.x