CVE-2023-26360

HIGH KEV NUCLEI

Adobe ColdFusion <2018 Update 15, 2021 Update 5 - RCE

Title source: llm

Description

Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.

Exploits (7)

nomisec WORKING POC 5 stars
by yosef0x01 · infoleak
https://github.com/yosef0x01/CVE-2023-26360
nomisec WORKING POC 5 stars
by jakabakos · remote
https://github.com/jakabakos/CVE-2023-26360-adobe-coldfusion-rce-exploit
nomisec WORKING POC 1 stars
by H3rm1tR3b0rn · remote
https://github.com/H3rm1tR3b0rn/CVE-2023-26360-RCE
nomisec WORKING POC 1 stars
by CuriousLearnerDev · poc
https://github.com/CuriousLearnerDev/ColdFusion_EXp
nomisec WORKING POC
by RyanRodrigues880 · remote
https://github.com/RyanRodrigues880/CVE-2023-26360
metasploit WORKING POC
by sf · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/adobe_coldfusion_fileread_cve_2023_26360.rb
metasploit WORKING POC EXCELLENT
by sf · rubypocjava
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/adobe_coldfusion_rce_cve_2023_26360.rb

Nuclei Templates (1)

Adobe ColdFusion - Local File Read
HIGHVERIFIEDby DhiyaneshDK,7own
Shodan: http.component:"Adobe ColdFusion" || http.component:"adobe coldfusion" || http.title:"coldfusion administrator login" || cpe:"cpe:2.3:a:adobe:coldfusion"
FOFA: title="coldfusion administrator login" || app="adobe-coldfusion"

Scores

CVSS v3 8.6
EPSS 0.9433
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Details

CISA KEV 2023-03-15
VulnCheck KEV 2023-03-14
InTheWild.io 2023-03-15
ENISA EUVD EUVD-2023-30181
CWE
CWE-284
Status published
Products (2)
adobe/coldfusion 2018 (16 CPE variants)
adobe/coldfusion 2021 (6 CPE variants)
Published Mar 23, 2023
KEV Added Mar 15, 2023
Tracked Since Feb 18, 2026