Description
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read and limited write access. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-06-30
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

ColdFusion versions 2025.9, 2023.20, and earlier contain a path traversal flaw (CWE-22) that can give an attacker the ability to read any file on the file system and to modify a restricted set of files. This weakness could be used to expose confidential configuration data, alter application logic, or undermine the integrity of the system. The flaw is classified as an improper limitation of a pathname to a restricted directory, and the CVSS score of 9.3 indicates a severe impact. Based on the description, it is inferred that the attacker does not need user interaction to exploit the vulnerability; a crafted request sent to the ColdFusion application is sufficient to trigger the flaw.

Affected Systems

The affected products are Adobe ColdFusion, specifically releases 2025.9, 2023.20, and all earlier versions. Any system running these versions and not updated to a fixed release is susceptible to the path traversal attack.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.3, and its EPSS score is not available, yet the lack of user interaction and the remote nature of the attack mean that exploitation can occur over the Web with minimal effort. The issue is not listed in CISA's KEV catalog, but the scope change indicates that components beyond the originating context can be affected, raising the overall risk. The likely attack vector, based on the description, is a remote web-based attack where an attacker supplies a specially crafted path in a ColdFusion request to read or write unauthorized files.

Generated by OpenCVE AI on June 30, 2026 at 17:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Adobe ColdFusion to a version that includes the path traversal fix, following the guidance in Adobe's advisory.
  • Configure the ColdFusion application and web server to validate all file paths and enforce directory boundaries, ensuring that only intended directories are accessible.
  • Harden the file system permissions so that the ColdFusion service has write access only to authorized directories, limiting the potential damage from any remaining write capability.

Generated by OpenCVE AI on June 30, 2026 at 17:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 30 Jun 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe coldfusion
Vendors & Products Adobe
Adobe coldfusion

Tue, 30 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 16:00:00 +0000

Type Values Removed Values Added
Description ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read and limited write access. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.
Title ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Adobe Coldfusion
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-06-30T16:08:32.189Z

Reserved: 2026-05-21T15:28:38.136Z

Link: CVE-2026-48313

cve-icon Vulnrichment

Updated: 2026-06-30T16:07:14.001Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-30T21:00:13Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')