**CVE-2023-29298** is a high-severity vulnerability rated **7.5/10** on the CVSS scale. Adobe ColdFusion versions **2018u16** (and earlier), **2021u6** (and earlier) and **2023.0.0.330468** (and earlier) are affected by an Improper Access Control vulnerability that could result in a **Security feature bypass**. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. CISA has confirmed active exploitation in the wild. EPSS estimates a **99.75%** chance of exploitation in the next 30 days.

## Description

Adobe ColdFusion versions **2018u16** (and earlier), **2021u6** (and earlier) and **2023.0.0.330468** (and earlier) are affected by an Improper Access Control vulnerability that could result in a **Security feature bypass**. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.

## Metrics

- **CVSS:** 3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- **EPSS Probability:** 99.75% (100.0th percentile)

Probability of exploitation in the next 30 days. [Learn more](https://www.first.org/epss/)

## Exploitation Status

This vulnerability is listed in CISA’s [Known Exploited Vulnerabilities](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) catalog, confirming active exploitation in the wild. Federal agencies must remediate by **Aug 10, 2023**.

## Weakness Enumeration

- [CWE-284](https://cwe.mitre.org/data/definitions/284.html)

## Affected Software

| Vendor | Product    | Versions |
| ------ | ---------- | -------- |
| Adobe  | Coldfusion | 2018     |
| Adobe  | Coldfusion | 2021     |
| Adobe  | Coldfusion | 2023     |

## References

- [Vendor Advisory](https://helpx.adobe.com/security/products/coldfusion/apsb23-40.html)
- [Third Party Advisory, US Government Resource](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-29298)

## Timeline

- **Published:** Jul 12, 2023
- **Last Modified:** Jun 17, 2026
- **Status:** Analyzed

## Frequently Asked Questions

### What is CVE-2023-29298?

### How severe is CVE-2023-29298?

CVE-2023-29298 has a CVSS score of **7.5/10** (HIGH severity). The EPSS model estimates a **99.75%** probability of exploitation in the next 30 days. This vulnerability is listed in CISA's **Known Exploited Vulnerabilities** catalog.

### How do I fix CVE-2023-29298?

Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also [run a Strix scan](https://app.strix.ai/) to test if your systems are affected.
