CVE-2025-30287: ColdFusion | Improper Authentication (CWE-287)
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code execution in the context of the current user. A low privileged attacker with local access could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction in that a victim must be coerced into performing actions within the application and scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30287?
CVE-2025-30287 has a high severity rating due to its potential for arbitrary code execution.
How do I fix CVE-2025-30287?
To fix CVE-2025-30287, update your Adobe ColdFusion to the latest version provided by Adobe.
What versions of Adobe ColdFusion are affected by CVE-2025-30287?
CVE-2025-30287 affects Adobe ColdFusion versions 2023.12, 2021.18, and 2025.0 and earlier.
What type of vulnerability is CVE-2025-30287?
CVE-2025-30287 is classified as an Improper Authentication vulnerability.
Can an attacker exploit CVE-2025-30287 remotely?
Yes, an attacker can exploit CVE-2025-30287 remotely to bypass authentication mechanisms.