Description
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Published: 2026-06-09
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

ColdFusion versions 2023.19, 2025.08 and earlier contain a path-traversal flaw (CWE-22) that allows a user to bypass directory restrictions and read or execute files located outside the intended sandbox. An attacker can craft a malicious attachment or file that, when opened by a victim on a system running the vulnerable ColdFusion instance, will cause the application to resolve the path to an unrestricted location. This leads to unauthorized disclosure of confidential data and potentially the execution of arbitrary code if the accessed files are executable or contain scripts. The vulnerability escalates scope and can compromise the confidentiality, integrity and availability of the affected systems.

Affected Systems

All instances of Adobe ColdFusion up to and including version 2023.19 and 2025.08 are affected. The issue is present in any deployment of those releases that have not been patched or upgraded beyond the referenced versions.

Risk and Exploitability

With a CVSS score of 8.8 the flaw is considered high severity. Because the EPSS score is not available, the precise likelihood of exploitation is uncertain, but the vulnerability is listed as not being in the CISA KEV catalog. Exploitation requires user interaction; a victim must open a crafted malicious file, making the primary attack vector local or remote via file delivery (e.g., email attachment or web download). Once the file is opened, the path traversal bypass allows reading or executing files outside the restricted area, giving the attacker a means to compromise the application and the underlying host.

Generated by OpenCVE AI on June 9, 2026 at 22:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a fixed version of ColdFusion that is newer than 2025.08 or apply the vendor-supplied patch
  • Disable or restrict the ColdFusion feature that allows arbitrary file loading by editing configuration settings or using access control lists
  • Implement input validation to reject any file paths containing ".." or absolute path indicators before they reach the ColdFusion file handler

Generated by OpenCVE AI on June 9, 2026 at 22:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 10 Jun 2026 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe coldfusion
Vendors & Products Adobe
Adobe coldfusion

Tue, 09 Jun 2026 21:15:00 +0000

Type Values Removed Values Added
Description ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Title ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Coldfusion
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-06-09T20:33:38.062Z

Reserved: 2026-05-20T15:50:31.361Z

Link: CVE-2026-47932

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-09T21:17:23.170

Modified: 2026-06-09T21:17:23.170

Link: CVE-2026-47932

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-10T01:15:18Z

Weaknesses