Vulnerability record · CVE-2023-29298 · published 12 July 2023
CVE-2023-29298: Adobe ColdFusion improper access control bypasses admin endpoint protection
Adobe · Coldfusion
Adobe ColdFusion 2018u16, 2021u6 and 2023.0.0.330468 (and earlier) contain an improper access control flaw that lets an unauthenticated attacker bypass a security feature and reach the administration CFM and CFC endpoints. Because those endpoints are normally restricted, the bypass exposes administrative functionality to anyone who can reach the server.
Description
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityThe flaw is unauthenticated, network-reachable, listed in CISA KEV with a near-maximum EPSS score, and grants access to administrative endpoints.
What it is
Adobe ColdFusion 2018u16, 2021u6 and 2023.0.0.330468 (and earlier) contain an improper access control flaw that lets an unauthenticated attacker bypass a security feature and reach the administration CFM and CFC endpoints. Because those endpoints are normally restricted, the bypass exposes administrative functionality to anyone who can reach the server.
Impact
An attacker gains unauthenticated access to ColdFusion administrative CFM and CFC endpoints, which can expose administrative functionality and data. The CVSS vector rates confidentiality as high with no integrity or availability impact.
Attack surface
The flaw is reachable over the network with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N and the description. Any internet- or network-exposed ColdFusion instance at the listed versions is in scope.
Exploitation
CVE-2023-29298 is listed in CISA KEV with a due date of 2023-08-10, and EPSS gives a 30-day probability of 0.99798 (99.957th percentile), indicating active exploitation. No ransomware campaign use is documented in the record.
What to do
- Apply the Adobe ColdFusion updates in advisory APSB23-40 for the affected 2018, 2021 and 2023 branches.
- If patching cannot be done immediately, follow the vendor mitigations in APSB23-40 or discontinue use of the product, as directed by CISA KEV.
- Restrict network access to ColdFusion administrative endpoints (CFM/CFC) to trusted management networks only.
- Audit and remove any external exposure of the ColdFusion administrator interface.
- Monitor for and review unexpected requests to administrative CFM and CFC paths.
Detection
- Review web and proxy logs for requests to ColdFusion administrative CFM/CFC endpoints from unauthenticated or unexpected sources.
- Alert on access to administrator paths from IP addresses outside approved management ranges.
- Correlate ColdFusion server logs with network traffic to identify access control bypass attempts.
- Hunt for post-exploitation activity following anomalous admin endpoint access on ColdFusion hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-29298 to the Known Exploited Vulnerabilities catalog on 20 July 2023 as "Adobe ColdFusion Improper Access Control Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 10 August 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://helpx.adobe.com/security/products/coldfusion/apsb23-40.html | Vendor Advisory |
| https://helpx.adobe.com/security/products/coldfusion/apsb23-40.html | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-29298 | Third Party AdvisoryUS Government Resource |
Track CVE-2023-29298 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-29298), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.