logo

Critical Access Control Bypass in Adobe ColdFusion (CVE-2023-29298)

ID: 54651516-4044-50c3-a84a-3a75381ef424

STIX ID: report--54651516-4044-50c3-a84a-3a75381ef424

Feed Name: ThreatCluster

Threat Score
78/100

Date Published: 2026-06-29

Date Updated: 2026-07-02

...
...

Rapid7 disclosed CVE-2023-29298, an access-control bypass in Adobe ColdFusion (2018u16, 2021u6, 2023) that allows unauthenticated attackers to access restricted admin endpoints and exposes numerous CFM/CFC files; Adobe issued patches (APSB23-40) and CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.