Description
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-06-30
Score: 10 Critical
EPSS: 28.6% Moderate
KEV: Yes
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper limitation of a pathname to a restricted directory (CWE-22) in Adobe ColdFusion allows an attacker to supply a specially crafted pathname that the server interprets outside the intended directory. The flaw can lead to arbitrary code execution in the context of the current user. Because the scope is changed, the compromise can affect the entire application and the underlying system.

Affected Systems

Adobe ColdFusion 2025.9, 2023.20, and all earlier releases are vulnerable unless patched or upgraded.

Risk and Exploitability

The CVSS score of 10 and the lack of a user‑interaction requirement mean an attacker can ColdFusion instance. The EPSS score of 29% indicates a high likelihood of exploitation. The vulnerability is listed in the CISA KEV catalog, underscoring real‑world exploitation risk. Because the scope is changed, a successful exploit can affect the entire application and the underlying operating system, making the threat more severe than a simple file‑inclusion. The attack vector is likely a remote web request that submits a crafted pathname to a ColdFusion resource.

Generated by OpenCVE AI on July 17, 2026 at 15:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Adobe ColdFusion update that contains the path‑traversal fix.
  • Restrict the directories accessible to ColdFusion, ensuring it can only read from a dedicated, safe base folder.
  • Disable or tightly restrict the ability to serve or include files from arbitrary paths, for example by configuring the server or using a WAF to block path‑traversal patterns.

Generated by OpenCVE AI on July 17, 2026 at 15:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2026-07-07T00:00:00+00:00', 'dueDate': '2026-07-10T00:00:00+00:00'}


Tue, 30 Jun 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe coldfusion
Vendors & Products Adobe
Adobe coldfusion

Tue, 30 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 16:00:00 +0000

Type Values Removed Values Added
Description ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Title ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Coldfusion
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-08T03:56:31.394Z

Reserved: 2026-05-21T15:28:38.134Z

Link: CVE-2026-48282

cve-icon Vulnrichment

Updated: 2026-06-30T16:05:06.230Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T15:15:16Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')