{"id":8840,"date":"2024-01-16T01:25:34","date_gmt":"2024-01-16T01:25:34","guid":{"rendered":"https:\/\/sekuritasit.com\/index.php\/2024\/01\/16\/adobe-coldfusion-access-control-bypass-cve-2023-26347-cve-2023-38205\/"},"modified":"2024-01-16T01:25:34","modified_gmt":"2024-01-16T01:25:34","slug":"adobe-coldfusion-access-control-bypass-cve-2023-26347-cve-2023-38205","status":"publish","type":"post","link":"https:\/\/sekuritasit.com\/index.php\/2024\/01\/16\/adobe-coldfusion-access-control-bypass-cve-2023-26347-cve-2023-38205\/","title":{"rendered":"Adobe ColdFusion Access Control Bypass (CVE-2023-26347, CVE-2023-38205)"},"content":{"rendered":"<p>What is the vulnerability?<br \/>\nAdobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by Improper Access Control vulnerabilities that could result in a Security feature bypass. According to the National Vulnerability Database (NVD), exploitation of this issue does not require user interaction. Exploitation of the vulnerabilities could give attacker access to the ColdFusion Administrator (CFM and CFC) endpoints.<\/p>\n<p>What is the Vendor Solution?<\/p>\n<p>Adobe released patches for the security bypass flaws in June 2023, find more information on CVE-2023-26347 at the following reference:<br \/>\n[Link] <\/p>\n<p> What FortiGuard Coverage is available?<\/p>\n<p>FortiGuard Labs has an IPS signature &#8220;&#8221;Adobe.ColdFusion.IPFilterUtils.Authentication.Bypass&#8221; in place for  CVE-2023-26347, CVE-2023-38205 since Aug 2023 and Endpoint Vulnerability signature to detect any vulnerable systems.<\/p>\n<p>FortiGuard Labs recommends companies to scan their environment, find vulnerable Adobe ColdFusion servers, and upgrade as per vendor advisory and always follow best practices.<a href=\"https:\/\/fortiguard.fortinet.com\/threat-signal-report\/5367\" target=\"_blank\" class=\"feedzy-rss-link-icon\" rel=\"noopener\">Read More<\/a>\u00a0<\/p>","protected":false},"excerpt":{"rendered":"<p>What is the vulnerability? Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by Improper Access Control vulnerabilities that could result in a Security feature bypass. According to the National Vulnerability Database (NVD), exploitation of this issue does not require user interaction. Exploitation of the vulnerabilities could give attacker access to the [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-8840","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.8 - aioseo.com -->\n\t<meta name=\"description\" content=\"What is the vulnerability? Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by Improper Access Control vulnerabilities that could result in a Security feature bypass. According to the National Vulnerability Database (NVD), exploitation of this issue does not require user interaction. Exploitation of the vulnerabilities could give attacker access to the\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/sekuritasit.com\/index.php\/2024\/01\/16\/adobe-coldfusion-access-control-bypass-cve-2023-26347-cve-2023-38205\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.8\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Sekuritas IT \u203a Creative solutions to unique challenges.\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Adobe ColdFusion Access Control Bypass (CVE-2023-26347, CVE-2023-38205) \u203a Sekuritas IT\" \/>\n\t\t<meta property=\"og:description\" content=\"What is the vulnerability? Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by Improper Access Control vulnerabilities that could result in a Security feature bypass. According to the National Vulnerability Database (NVD), exploitation of this issue does not require user interaction. Exploitation of the vulnerabilities could give attacker access to the\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/sekuritasit.com\/index.php\/2024\/01\/16\/adobe-coldfusion-access-control-bypass-cve-2023-26347-cve-2023-38205\/\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2024-01-16T01:25:34+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-01-16T01:25:34+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/profile.php?id=100086973577423\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Adobe ColdFusion Access Control Bypass (CVE-2023-26347, CVE-2023-38205) \u203a Sekuritas IT\" \/>\n\t\t<meta name=\"twitter:description\" content=\"What is the vulnerability? Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by Improper Access Control vulnerabilities that could result in a Security feature bypass. According to the National Vulnerability Database (NVD), exploitation of this issue does not require user interaction. Exploitation of the vulnerabilities could give attacker access to the\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/2024\\\/01\\\/16\\\/adobe-coldfusion-access-control-bypass-cve-2023-26347-cve-2023-38205\\\/#blogposting\",\"name\":\"Adobe ColdFusion Access Control Bypass (CVE-2023-26347, CVE-2023-38205) \\u203a Sekuritas IT\",\"headline\":\"Adobe ColdFusion Access Control Bypass (CVE-2023-26347, CVE-2023-38205)\",\"author\":{\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/author\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/#organization\"},\"datePublished\":\"2024-01-16T01:25:34+00:00\",\"dateModified\":\"2024-01-16T01:25:34+00:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/2024\\\/01\\\/16\\\/adobe-coldfusion-access-control-bypass-cve-2023-26347-cve-2023-38205\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/2024\\\/01\\\/16\\\/adobe-coldfusion-access-control-bypass-cve-2023-26347-cve-2023-38205\\\/#webpage\"},\"articleSection\":\"Uncategorized\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/2024\\\/01\\\/16\\\/adobe-coldfusion-access-control-bypass-cve-2023-26347-cve-2023-38205\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sekuritasit.com#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/sekuritasit.com\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/category\\\/uncategorized\\\/#listItem\",\"name\":\"Uncategorized\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/category\\\/uncategorized\\\/#listItem\",\"position\":2,\"name\":\"Uncategorized\",\"item\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/category\\\/uncategorized\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/2024\\\/01\\\/16\\\/adobe-coldfusion-access-control-bypass-cve-2023-26347-cve-2023-38205\\\/#listItem\",\"name\":\"Adobe ColdFusion Access Control Bypass (CVE-2023-26347, CVE-2023-38205)\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sekuritasit.com#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/2024\\\/01\\\/16\\\/adobe-coldfusion-access-control-bypass-cve-2023-26347-cve-2023-38205\\\/#listItem\",\"position\":3,\"name\":\"Adobe ColdFusion Access Control Bypass (CVE-2023-26347, CVE-2023-38205)\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/category\\\/uncategorized\\\/#listItem\",\"name\":\"Uncategorized\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/#organization\",\"name\":\"Sekuritas IT\",\"description\":\"Creative solutions to unique challenges.\",\"url\":\"https:\\\/\\\/sekuritasit.com\\\/\",\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/profile.php?id=100086973577423\"]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/2024\\\/01\\\/16\\\/adobe-coldfusion-access-control-bypass-cve-2023-26347-cve-2023-38205\\\/#webpage\",\"url\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/2024\\\/01\\\/16\\\/adobe-coldfusion-access-control-bypass-cve-2023-26347-cve-2023-38205\\\/\",\"name\":\"Adobe ColdFusion Access Control Bypass (CVE-2023-26347, CVE-2023-38205) \\u203a Sekuritas IT\",\"description\":\"What is the vulnerability? Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by Improper Access Control vulnerabilities that could result in a Security feature bypass. According to the National Vulnerability Database (NVD), exploitation of this issue does not require user interaction. Exploitation of the vulnerabilities could give attacker access to the\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/2024\\\/01\\\/16\\\/adobe-coldfusion-access-control-bypass-cve-2023-26347-cve-2023-38205\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/author\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/author\\\/#author\"},\"datePublished\":\"2024-01-16T01:25:34+00:00\",\"dateModified\":\"2024-01-16T01:25:34+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/#website\",\"url\":\"https:\\\/\\\/sekuritasit.com\\\/\",\"name\":\"Sekuritas IT\",\"alternateName\":\"Sekuritas\",\"description\":\"Creative solutions to unique challenges.\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Adobe ColdFusion Access Control Bypass (CVE-2023-26347, CVE-2023-38205) \u203a Sekuritas IT","description":"What is the vulnerability? Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by Improper Access Control vulnerabilities that could result in a Security feature bypass. According to the National Vulnerability Database (NVD), exploitation of this issue does not require user interaction. Exploitation of the vulnerabilities could give attacker access to the","canonical_url":"https:\/\/sekuritasit.com\/index.php\/2024\/01\/16\/adobe-coldfusion-access-control-bypass-cve-2023-26347-cve-2023-38205\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/sekuritasit.com\/index.php\/2024\/01\/16\/adobe-coldfusion-access-control-bypass-cve-2023-26347-cve-2023-38205\/#blogposting","name":"Adobe ColdFusion Access Control Bypass (CVE-2023-26347, CVE-2023-38205) \u203a Sekuritas IT","headline":"Adobe ColdFusion Access Control Bypass (CVE-2023-26347, CVE-2023-38205)","author":{"@id":"https:\/\/sekuritasit.com\/index.php\/author\/#author"},"publisher":{"@id":"https:\/\/sekuritasit.com\/#organization"},"datePublished":"2024-01-16T01:25:34+00:00","dateModified":"2024-01-16T01:25:34+00:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/sekuritasit.com\/index.php\/2024\/01\/16\/adobe-coldfusion-access-control-bypass-cve-2023-26347-cve-2023-38205\/#webpage"},"isPartOf":{"@id":"https:\/\/sekuritasit.com\/index.php\/2024\/01\/16\/adobe-coldfusion-access-control-bypass-cve-2023-26347-cve-2023-38205\/#webpage"},"articleSection":"Uncategorized"},{"@type":"BreadcrumbList","@id":"https:\/\/sekuritasit.com\/index.php\/2024\/01\/16\/adobe-coldfusion-access-control-bypass-cve-2023-26347-cve-2023-38205\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/sekuritasit.com#listItem","position":1,"name":"Home","item":"https:\/\/sekuritasit.com","nextItem":{"@type":"ListItem","@id":"https:\/\/sekuritasit.com\/index.php\/category\/uncategorized\/#listItem","name":"Uncategorized"}},{"@type":"ListItem","@id":"https:\/\/sekuritasit.com\/index.php\/category\/uncategorized\/#listItem","position":2,"name":"Uncategorized","item":"https:\/\/sekuritasit.com\/index.php\/category\/uncategorized\/","nextItem":{"@type":"ListItem","@id":"https:\/\/sekuritasit.com\/index.php\/2024\/01\/16\/adobe-coldfusion-access-control-bypass-cve-2023-26347-cve-2023-38205\/#listItem","name":"Adobe ColdFusion Access Control Bypass (CVE-2023-26347, CVE-2023-38205)"},"previousItem":{"@type":"ListItem","@id":"https:\/\/sekuritasit.com#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/sekuritasit.com\/index.php\/2024\/01\/16\/adobe-coldfusion-access-control-bypass-cve-2023-26347-cve-2023-38205\/#listItem","position":3,"name":"Adobe ColdFusion Access Control Bypass (CVE-2023-26347, CVE-2023-38205)","previousItem":{"@type":"ListItem","@id":"https:\/\/sekuritasit.com\/index.php\/category\/uncategorized\/#listItem","name":"Uncategorized"}}]},{"@type":"Organization","@id":"https:\/\/sekuritasit.com\/#organization","name":"Sekuritas IT","description":"Creative solutions to unique challenges.","url":"https:\/\/sekuritasit.com\/","sameAs":["https:\/\/www.facebook.com\/profile.php?id=100086973577423"]},{"@type":"WebPage","@id":"https:\/\/sekuritasit.com\/index.php\/2024\/01\/16\/adobe-coldfusion-access-control-bypass-cve-2023-26347-cve-2023-38205\/#webpage","url":"https:\/\/sekuritasit.com\/index.php\/2024\/01\/16\/adobe-coldfusion-access-control-bypass-cve-2023-26347-cve-2023-38205\/","name":"Adobe ColdFusion Access Control Bypass (CVE-2023-26347, CVE-2023-38205) \u203a Sekuritas IT","description":"What is the vulnerability? Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by Improper Access Control vulnerabilities that could result in a Security feature bypass. According to the National Vulnerability Database (NVD), exploitation of this issue does not require user interaction. Exploitation of the vulnerabilities could give attacker access to the","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/sekuritasit.com\/#website"},"breadcrumb":{"@id":"https:\/\/sekuritasit.com\/index.php\/2024\/01\/16\/adobe-coldfusion-access-control-bypass-cve-2023-26347-cve-2023-38205\/#breadcrumblist"},"author":{"@id":"https:\/\/sekuritasit.com\/index.php\/author\/#author"},"creator":{"@id":"https:\/\/sekuritasit.com\/index.php\/author\/#author"},"datePublished":"2024-01-16T01:25:34+00:00","dateModified":"2024-01-16T01:25:34+00:00"},{"@type":"WebSite","@id":"https:\/\/sekuritasit.com\/#website","url":"https:\/\/sekuritasit.com\/","name":"Sekuritas IT","alternateName":"Sekuritas","description":"Creative solutions to unique challenges.","inLanguage":"en-US","publisher":{"@id":"https:\/\/sekuritasit.com\/#organization"}}]},"og:locale":"en_US","og:site_name":"Sekuritas IT \u203a Creative solutions to unique challenges.","og:type":"article","og:title":"Adobe ColdFusion Access Control Bypass (CVE-2023-26347, CVE-2023-38205) \u203a Sekuritas IT","og:description":"What is the vulnerability? Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by Improper Access Control vulnerabilities that could result in a Security feature bypass. According to the National Vulnerability Database (NVD), exploitation of this issue does not require user interaction. Exploitation of the vulnerabilities could give attacker access to the","og:url":"https:\/\/sekuritasit.com\/index.php\/2024\/01\/16\/adobe-coldfusion-access-control-bypass-cve-2023-26347-cve-2023-38205\/","article:published_time":"2024-01-16T01:25:34+00:00","article:modified_time":"2024-01-16T01:25:34+00:00","article:publisher":"https:\/\/www.facebook.com\/profile.php?id=100086973577423","twitter:card":"summary_large_image","twitter:title":"Adobe ColdFusion Access Control Bypass (CVE-2023-26347, CVE-2023-38205) \u203a Sekuritas IT","twitter:description":"What is the vulnerability? Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by Improper Access Control vulnerabilities that could result in a Security feature bypass. According to the National Vulnerability Database (NVD), exploitation of this issue does not require user interaction. Exploitation of the vulnerabilities could give attacker access to the"},"aioseo_meta_data":{"post_id":"8840","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2024-01-16 03:56:04","updated":"2025-10-15 06:41:00","seo_analyzer_scan_date":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/sekuritasit.com\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/sekuritasit.com\/index.php\/category\/uncategorized\/\" title=\"Uncategorized\">Uncategorized<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tAdobe ColdFusion Access Control Bypass (CVE-2023-26347, CVE-2023-38205)\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/sekuritasit.com"},{"label":"Uncategorized","link":"https:\/\/sekuritasit.com\/index.php\/category\/uncategorized\/"},{"label":"Adobe ColdFusion Access Control Bypass (CVE-2023-26347, CVE-2023-38205)","link":"https:\/\/sekuritasit.com\/index.php\/2024\/01\/16\/adobe-coldfusion-access-control-bypass-cve-2023-26347-cve-2023-38205\/"}],"_links":{"self":[{"href":"https:\/\/sekuritasit.com\/index.php\/wp-json\/wp\/v2\/posts\/8840","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sekuritasit.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sekuritasit.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/sekuritasit.com\/index.php\/wp-json\/wp\/v2\/comments?post=8840"}],"version-history":[{"count":0,"href":"https:\/\/sekuritasit.com\/index.php\/wp-json\/wp\/v2\/posts\/8840\/revisions"}],"wp:attachment":[{"href":"https:\/\/sekuritasit.com\/index.php\/wp-json\/wp\/v2\/media?parent=8840"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sekuritasit.com\/index.php\/wp-json\/wp\/v2\/categories?post=8840"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sekuritasit.com\/index.php\/wp-json\/wp\/v2\/tags?post=8840"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}