
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-71383 is an Incorrect Authorization (CWE-863) vulnerability in Adobe ColdFusion that allows unauthenticated remote attackers to bypass security controls and gain limited unauthorized read and write access, with a limited disruption to availability. It affects Adobe ColdFusion 2023 (all updates through 2023.0.22) and ColdFusion 2025 (all updates through 2025.0.11). The vulnerability was published on August 11, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 7.3 (High) (GitHub Advisory, Adobe Advisory).
The vulnerability is rooted in improper authorization checks (CWE-863) within Adobe ColdFusion's request handling logic, where the product fails to correctly verify whether an actor is authorized to access certain resources or perform specific actions. An unauthenticated attacker can exploit this over the network with low attack complexity and no user interaction required, making it automatable. The flaw enables a security feature bypass, granting limited unauthorized read and write access to affected ColdFusion resources (GitHub Advisory, Adobe Advisory).
Successful exploitation allows an unauthenticated network attacker to bypass security controls and gain limited unauthorized read and write access to ColdFusion resources, as well as cause a limited disruption to service availability. The technical impact is assessed as partial, affecting confidentiality, integrity, and availability at a low level each. While the scope is unchanged (no cross-component escalation), the no-authentication, no-interaction requirement significantly lowers the barrier for exploitation (GitHub Advisory, Adobe Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The vulnerability is classified as automatable by NVD SSVC assessment, meaning it can be exploited at scale without manual interaction. The EPSS score is approximately 0.266% (19th percentile), indicating a relatively low near-term exploitation probability. No threat actor attribution has been reported, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Adobe has released patched versions addressing this vulnerability: ColdFusion 2023 Update 23 (version 2023.0.23) and ColdFusion 2025 Update 12 (version 2025.0.12). Administrators should apply these updates immediately via the Adobe security bulletin. Additionally, reviewing and strengthening access controls and authorization mechanisms in ColdFusion deployments, and monitoring for anomalous unauthorized read/write activity, are recommended as complementary measures (Adobe Advisory).
The vulnerability was covered by several cybersecurity news outlets following Adobe's August 2026 patch release, including CyberSecurityNews and GBHackers, in the context of broader Adobe ColdFusion vulnerabilities allowing arbitrary code execution. The Center for Internet Security (CIS) issued an advisory noting multiple vulnerabilities in Adobe products that could allow for arbitrary code execution. Coverage was largely informational, with no notable researcher controversy or significant social media debate observed (CIS Advisory, CyberSecurityNews).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."