CVE-2026-71384
Status: AnalyzedCritical (9.6)—
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, potentially resulting in an application denial-of-service condition. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Base score: 9.6
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.46%
- Percentile among all scored CVEs: 37
- Score date: 10/1/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-863
References
Raw JSON (NVD)
Show
{
"id": "CVE-2026-71384",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-71384",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-08-12T14:39:36.439123Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@adobe.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 9.6,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "psirt@adobe.com",
"affectedData": [
{
"vendor": "Adobe",
"product": "ColdFusion 2025",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "2025.0.11"
},
{
"status": "unaffected",
"version": "2025.0.12",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Adobe",
"product": "ColdFusion 2023",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "2023.0.22"
},
{
"status": "unaffected",
"version": "2023.0.23",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-08-11T17:19:13.593",
"references": [
{
"url": "https://helpx.adobe.com/security/products/coldfusion/apsb26-90.html",
"tags": [
"Vendor Advisory"
],
"source": "psirt@adobe.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@adobe.com",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, potentially resulting in an application denial-of-service condition. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed."
}
],
"lastModified": "2026-08-28T00:18:09.730",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B02A37FE-5D31-4892-A3E6-156A8FE62D28"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0AA3D302-CFEE-4DFD-AB92-F53C87721BFF"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update10:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "645D1B5F-2DAB-4AB8-A465-AC37FF494F95"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update11:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ED6D8996-0770-4C9F-BEA5-87EA479D40A5"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update12:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4836086E-3D4A-4A07-A372-382D385CB490"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update13:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CBC19168-4184-4B59-B9C8-E98844124EED"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update14:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A60DCD92-9A5B-411C-9554-642C91D77FAE"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update15:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "58CC65EF-60A3-4DFA-AA51-E5013F116CEA"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update16:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2E3EBFB1-4488-4924-A2E2-B7E422D68345"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update17:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A683F9B2-A0DC-4AA0-BE97-9E74FA200AB1"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update18:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8689F35F-9A81-45D2-B782-DBA12306BA45"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update19:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5FAA5985-4B25-46C5-8064-0713AB251704"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EB88D4FE-5496-4639-BAF2-9F29F24ABF29"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update20:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9E3884AF-7A1A-4604-B653-6694B7BD1E86"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update21:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "914DDD70-EF8D-4D0F-B4E2-ABCA14337EB4"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update22:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F277616E-64A7-4801-BBB6-D01AF5761951"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "43E0ED98-2C1F-40B8-AF60-FEB1D85619C0"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "76204873-C6E0-4202-8A03-0773270F1802"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C1A22BE9-0D47-4BA8-8BDB-9B12D7A0F7C7"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E3A83642-BF14-4C37-BD94-FA76AABE8ADC"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A892E1DC-F2C8-4F53-8580-A2D1BEED5A25"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update8:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DB97ADBA-C1A9-4EE0-9509-68CB12358AE5"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update9:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E17C38F0-9B0F-4433-9CBD-6E3D63EA9BDC"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2025:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "30779417-D4E5-4A01-BE0E-1CE1D134292A"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2025:update1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "80D7FC6A-F264-4CB1-A18D-B091EBA47882"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2025:update10:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C39E4812-C14C-4E3F-BD27-947F51C18308"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2025:update11:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0C946E44-D23D-409B-B770-AAB269A4136C"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2025:update2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E3DA0D20-93BA-4C76-A400-159853CD7277"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2025:update3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5BAB6F21-61F1-43AB-88BA-553CD9AD6C0E"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2025:update4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C85288B9-5D63-49EA-828A-8DB3BB2367F6"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2025:update5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3882A011-5A01-48E7-B5E7-5A837B1CE245"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2025:update6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AACCE621-3380-4144-BA1B-AA26FE96B902"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2025:update7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EBC62370-3FA2-4AF7-A201-4155D09051F3"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2025:update8:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D7616F34-9422-4815-806F-4484F68ED2A8"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2025:update9:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FB078BC9-164F-46D0-99F8-086F93FF2046"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@adobe.com"
}