CVE-2025-61811: ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. A high privileged attacker could leverage this vulnerability to bypass security measures and execute malicious code. Exploitation of this issue does not require user interaction and scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61811?
CVE-2025-61811 has a high severity rating due to its potential for arbitrary code execution.
How do I fix CVE-2025-61811?
To fix CVE-2025-61811, update Adobe ColdFusion to the latest version beyond 2025.4.
What versions of ColdFusion are affected by CVE-2025-61811?
CVE-2025-61811 affects Adobe ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier.
What type of vulnerability is CVE-2025-61811?
CVE-2025-61811 is classified as an Improper Access Control vulnerability.
What can attackers achieve by exploiting CVE-2025-61811?
By exploiting CVE-2025-61811, attackers could execute arbitrary code in the context of the current user.