CVE-2025-49551: ColdFusion | Use of Hard-coded Credentials (CWE-798)
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Use of Hard-coded Credentials vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized access to sensitive systems or data. Exploitation of this issue does not require user interaction. The vulnerable component is restricted to internal IP addresses.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49551?
CVE-2025-49551 has been classified with a severity level indicating significant potential for privilege escalation.
How do I fix CVE-2025-49551?
To fix CVE-2025-49551, it is recommended to update Adobe ColdFusion to the latest version available.
What versions of ColdFusion are affected by CVE-2025-49551?
Adobe ColdFusion versions 2025.2, 2023.14, and 2021.20 and earlier are affected by CVE-2025-49551.
What is the impact of exploiting CVE-2025-49551?
Exploiting CVE-2025-49551 can lead to unauthorized access to sensitive systems or data due to privilege escalation.
What kind of vulnerability is CVE-2025-49551?
CVE-2025-49551 is identified as a Use of Hard-coded Credentials vulnerability.