CVE-2025-30288: ColdFusion | Improper Access Control (CWE-284)
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low privileged attacker with local access could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction in that a victim must be coerced into performing actions within the application and scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30288?
CVE-2025-30288 is classified as a critical vulnerability due to its potential to allow unauthorized access.
How do I fix CVE-2025-30288?
To fix CVE-2025-30288, update Adobe ColdFusion to the latest patched version.
Which versions of ColdFusion are affected by CVE-2025-30288?
CVE-2025-30288 affects Adobe ColdFusion versions 2023.12, 2021.18, and 2025.0 and earlier.
What types of attacks can exploit CVE-2025-30288?
CVE-2025-30288 can be exploited to perform security feature bypass attacks.
What are the consequences of exploiting CVE-2025-30288?
Exploitation of CVE-2025-30288 could allow attackers to gain unauthorized access to sensitive data.