Improper access control in ColdFusion - CVE-2023-26360
Published: March 14, 2023 / Updated: October 25, 2024
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote attacker can bypass implemented security restrictions and gain unauthorized access to the application.
Note, the vulnerability is being actively exploited in the wild.
Affected software
How to mitigate CVE-2023-26360
Links to Public Exploits and PoC-codes
- Exploit #10721 - Adobe ColdFusion versions 2018_15 (and earlier) and 2021_5 and earlier - Arbitrary File Read (October 25, 2024)
- Exploit #9930 - CVE-2023-26360-adobe-coldfusion-rce-exploit () (June 7, 2024)
- Exploit #9017 - Adobe ColdFusion Unauthenticated Remote Code Execution (April 28, 2023)
- Exploit #9018 - Adobe ColdFusion Unauthenticated Arbitrary File Read (April 28, 2023)