---
id: CVE-2026-83961
title: >-
  ColdFusion is affected by an Improper Authentication vulnerability that could
  result in privilege escalation
summary: >-
  ColdFusion is affected by an Improper Authentication vulnerability that could
  result in privilege escalation. An attacker could leverage this vulnerability
  to gain limited read and write access. The vulnerable component is restricted
  to …
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L'
cwe:
  - CWE-287
vendor: adobe
product: coldfusion
affected:
  - coldfusion = 2023
  - coldfusion = 2025
published: '2026-09-03'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T13:33:43.513'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-83961'
references:
  - url: 'https://helpx.adobe.com/security/products/coldfusion/apsb26-90.html'
    label: psirt@adobe.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-03T16:09:32.181370Z'
ingestedAt: '2026-09-10T20:38:09.358Z'
epss: 0.00418
epssPercentile: 0.33433
---

## Overview

ColdFusion is affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain limited read and write access. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.

## Affected

- `coldfusion = 2023`
- `coldfusion = 2025`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
