CRITICAL

CVE-2026-48282

Adobe Coldfusion 2026-06-30 CVSS v3.1
CVSS
10
KEV

Description

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Summary dbcve.org

ColdFusion versions 2025.9, 2023.20 and earlier contain a path traversal vulnerability that allows attackers to access files outside the restricted directory through manipulated path inputs, leading to arbitrary code execution in the context of the current user. No user interaction is required for exploitation, and the CVSS scope change indicates the vulnerability impacts components beyond the original security boundary.

Mitigation

Immediately restrict file path inputs through strict allow-list validation, implement proper path canonicalization to resolve symlinks and relative paths, and apply Adobe's security patches for the affected ColdFusion versions. Until patched, disable unnecessary file operation endpoints.

Weakness (CWE)

CWE-22 Path Traversal

EPSS Score

42.39%
Probability of exploitation in next 30 days
98.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE