CVE-2023-26347: CVE-2023-38205 issues | ColdFusion Admin Panel Access
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-26347?
The severity of CVE-2023-26347 is high with a severity value of 7.5.
What is the affected software for CVE-2023-26347?
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by CVE-2023-26347.
How does CVE-2023-26347 impact Adobe ColdFusion?
CVE-2023-26347 is an Improper Access Control vulnerability that could result in a Security feature bypass, allowing an unauthenticated attacker to access the administration CFM and CFC endpoints in Adobe ColdFusion.
What is the fix for CVE-2023-26347?
To fix CVE-2023-26347, it is recommended to update Adobe ColdFusion to the latest version available.
Where can I find more information on CVE-2023-26347?
You can find more information on CVE-2023-26347 at the following reference link: [https://helpx.adobe.com/security/products/coldfusion/apsb23-52.html](https://helpx.adobe.com/security/products/coldfusion/apsb23-52.html)