Description
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction.
Published: 2026-04-14
Score: 8.6 High
EPSS: 26.3% Moderate
KEV: No
Impact: Arbitrary file system read via path traversal
Action: Immediate Patch
AI Analysis

Impact

ColdFusion versions 2023.18, 2025.6 and all earlier releases contain a path‑traversal flaw that permits attackers to read files outside the intended directory. The vulnerability enables remote arbitrary file access without user interaction.

Affected Systems

The affected product is Adobe ColdFusion, all versions up to 2025.6 inclusive, including the releases listed in the CPE set such as 2023 and 2025 with update branches.

Risk and Exploitability

The CVSS score of 8.6 reflects a high‑severity risk, and the EPSS of 26% indicates a relatively high probability that the vulnerability will be exploited. Based on the description, it is inferred that the flaw can be triggered by a crafted request to a ColdFusion file‑access endpoint, allowing an unauthenticated attacker to obtain sensitive files remotely. The vulnerability is not currently catalogued in CISA KEV, but the combination of high severity, broad impact, and exploit likelihood warrants prompt mitigation.

Generated by OpenCVE AI on September 10, 2026 at 14:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest ColdFusion security update (APSB26‑38) released by Adobe to mitigate the path‑traversal flaw.
  • If the patch cannot be applied immediately, restrict or disable ColdFusion endpoints that accept arbitrary file paths, limiting access to a dedicated safe directory.
  • Enforce strict authentication and authorization on any file‑access endpoint to ensure only privileged users can request file content.
  • Deploy a web application firewall or implement request filtering rules that block path‑traversal patterns before they reach the application.

Generated by OpenCVE AI on September 10, 2026 at 14:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Apr 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:adobe:coldfusion:2023:-:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update10:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update11:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update12:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update13:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update14:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update15:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update16:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update17:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update18:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update1:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update2:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update3:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update4:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update5:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update6:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update7:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update8:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2023:update9:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:-:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update1:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update2:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update3:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update4:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update5:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2025:update6:*:*:*:*:*:*

Thu, 16 Apr 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Apr 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe coldfusion
Vendors & Products Adobe
Adobe coldfusion

Tue, 14 Apr 2026 22:00:00 +0000

Type Values Removed Values Added
Description ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction.
Title ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Adobe Coldfusion
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:15:59.110Z

Reserved: 2026-02-18T22:02:41.401Z

Link: CVE-2026-27305

cve-icon Vulnrichment

Updated: 2026-04-16T13:09:49.205Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-14T22:16:29.573

Modified: 2026-08-28T00:17:14.150

Link: CVE-2026-27305

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T15:00:15Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')