Products
Government
Resources
Community
Company
Partners
Sign In / Join
Sign In
Advisories
Lucee Admin Interface Authenticated Remote Code Execution via Scheduled Job File Write
Go Back
severity
critical
date
July 2, 2025
Affecting
Lucee 5.x
Lucee 6.x
All versions with scheduled task functionality
CVE
CVE-2025-34074
CVE type
Code Injection
CVSS
9.4
CVSS V4 Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
References
Metasploit Module
Lucee GitHub Repo
Credit
Alexander Philiotis of SynerComm