CVE-2026-25652: ColdFusion | Incorrect Authorization (CWE-863)
Published Aug 11, 2026
·Updated
is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain unauthorized read and write access. Exploitation of this issue does not require user interaction.
Affected Software
1 affected component
Adobe ColdFusion
Event History
Aug 11, 2026
CVE Published
via MITRE·04:30 PM
Data Sourced
via MITRE·04:30 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-25652?
The severity of CVE-2026-25652 is rated as high, with a score of 7.8.
2
How do I fix CVE-2026-25652?
To fix CVE-2026-25652, apply the latest security updates provided by Adobe for ColdFusion.
3
What impact does CVE-2026-25652 have on Adobe ColdFusion?
CVE-2026-25652 allows a low-privileged attacker to achieve unauthorized read and write access, leading to privilege escalation.
4
Does CVE-2026-25652 require user interaction for exploitation?
No, exploitation of CVE-2026-25652 does not require any user interaction.
5
What is the nature of the vulnerability in CVE-2026-25652?
CVE-2026-25652 is an Incorrect Authorization vulnerability, classified under CWE-863.