Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.6
CVE-2026-71384: is affected by Security Feature Bypass on Administrative Network
CVE-2026-71384
CVE-2026-71384
Summary
This issue affects a component of is, which is typically restricted to an administrative network. An attacker could bypass security measures to gain unauthorized access, potentially causing the application to become unavailable. To mitigate this risk, ensure the component is properly configured and restricted to authorized users and networks.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| adobe | coldfusion 2025 | <= 2025.0.11 |
| adobe | coldfusion 2023 | <= 2023.0.22 |
Original title
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthoriz...
Original description
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, potentially resulting in an application denial-of-service condition. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.
mitre CVSS3.1
9.6
Vulnerability type
CWE-863
Incorrect Authorization
Published: 11 Aug 2026 · Updated: 11 Aug 2026 · First seen: 11 Aug 2026