Vulnerability record · CVE-2023-38205 · published 14 September 2023
CVE-2023-38205: Adobe ColdFusion improper access control bypasses admin endpoint protection
Adobe · Coldfusion
Adobe ColdFusion 2018u18, 2021u8 and 2023u2 (and earlier) contain an improper access control flaw that lets an attacker bypass a security feature and reach administration CFM and CFC endpoints. Because the admin interface is normally restricted, this exposure matters: it is remotely reachable without credentials or user interaction and is listed in CISA KEV.
Description
Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityIt is in CISA KEV with a near-maximum EPSS score and allows unauthenticated remote access to administrative endpoints.
What it is
Adobe ColdFusion 2018u18, 2021u8 and 2023u2 (and earlier) contain an improper access control flaw that lets an attacker bypass a security feature and reach administration CFM and CFC endpoints. Because the admin interface is normally restricted, this exposure matters: it is remotely reachable without credentials or user interaction and is listed in CISA KEV.
Impact
An attacker gains unauthorized access to ColdFusion administrative CFM and CFC endpoints, exposing administrative functionality and any data those endpoints return. The CVSS vector indicates a high confidentiality impact with no integrity or availability effect.
Attack surface
Reachable over the network via HTTP requests to the ColdFusion administrative CFM and CFC endpoints; the vector shows no privileges required and no user interaction. No authentication is needed per the CVSS vector and description.
Exploitation
CISA added it to KEV on 2023-07-20 with a 2023-08-10 remediation due date, and EPSS is 0.99742 (99.954th percentile), indicating active exploitation and very high likelihood. No ransomware campaign use is documented in the record.
What to do
- Apply the Adobe ColdFusion updates in security bulletin APSB23-47 for the affected 2018, 2021 and 2023 releases.
- If patching cannot be done immediately, follow CISA's required action and the vendor's mitigations, or discontinue use of the product where mitigations are unavailable.
- Restrict network access to ColdFusion administrative CFM and CFC endpoints so they are not reachable from untrusted networks.
- Verify the ColdFusion administrator interface is not internet-exposed and enforce authentication and IP allowlisting in front of it.
- Review ColdFusion configuration and logs for unauthorized changes after exposure.
Detection
- Hunt web and proxy logs for requests to ColdFusion administrative CFM and CFC paths from unexpected or external source IPs.
- Alert on access to admin endpoints that returns HTTP 200 without a prior successful authentication event.
- Monitor ColdFusion logs for anomalous administrative activity or configuration changes outside normal maintenance windows.
- Correlate endpoint and web logs for post-exploitation behavior on ColdFusion hosts, such as new files or processes spawned by the ColdFusion service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-38205 to the Known Exploited Vulnerabilities catalog on 20 July 2023 as "Adobe ColdFusion Improper Access Control Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 10 August 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://helpx.adobe.com/security/products/coldfusion/apsb23-47.html | Vendor Advisory |
| https://helpx.adobe.com/security/products/coldfusion/apsb23-47.html | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-38205 | Third Party AdvisoryUS Government Resource |
Track CVE-2023-38205 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-38205), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.