CVE-2025-43565: ColdFusion | Incorrect Authorization (CWE-863)
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction and scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43565?
CVE-2025-43565 has been classified as a high severity vulnerability.
How do I fix CVE-2025-43565?
To mitigate CVE-2025-43565, update to Adobe ColdFusion version 2025.2 or later.
What type of vulnerability is CVE-2025-43565?
CVE-2025-43565 is an Incorrect Authorization vulnerability that can lead to arbitrary code execution.
Who is affected by CVE-2025-43565?
CVE-2025-43565 affects Adobe ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier.
What could exploitation of CVE-2025-43565 allow an attacker to do?
Exploitation of CVE-2025-43565 could allow a high-privileged attacker to bypass security protections and execute arbitrary code.