CVE-2025-34074 - CVE House
Back to Database
Status published Critical CVE-2025-34074

Lucee Admin Interface Authenticated Remote Code Execution via Scheduled Job File Write

Vulnerability Description

An authenticated remote code execution vulnerability exists in Lucee’s administrative interface due to insecure design in the scheduled task functionality. An administrator with access to /lucee/admin/web.cfm can configure a scheduled job to retrieve a remote .cfm file from an attacker-controlled server, which is written to the Lucee webroot and executed with the privileges of the Lucee service account. Because Lucee does not enforce integrity checks, path restrictions, or execution controls for scheduled task fetches, this feature can be abused to achieve arbitrary code execution. This issue is distinct from CVE-2024-55354.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-34074

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Alexander Philiotis of SynerComm

Affected Vendor

Lucee Association Switzerland

View all reports →

Affected Software

Lucee
Vulnerable Versions:
5.0, 6.0, All versions with scheduled task functionality

Timeline

Official Publish: July 2nd, 2025
Last Modified: March 23rd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)