Description
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read and limited write access. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-06-30
Score: 9.3 Critical
EPSS: 1.6% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

ColdFusion versions 2025.9, 2023.20, and earlier contain a path traversal flaw (CWE‑22) that can give an attacker the ability to read any file on the file system set of files. This weakness could be used to expose confidential configuration data, alter application logic, or undermine the integrity of the system. The flaw is classified as an improper limitation of a pathname to a restricted directory, and the CVSS score of 9.3 indicates a severe impact to the ColdFusion application is sufficient to trigger the flaw.

Affected Systems

The affected products are Adobe ColdFusion, specifically releases 2025.9, 2023.20 and earlier versions that have not been updated to a fixed release.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.3, and its EPSS score of 2% indicates a very small but non‑zero likelihood of exploitation, yet the lack of user interaction and the remote nature of the attack mean that exploitation can occur over the Web with minimal effort. The issue is not listed in CISA's KEV catalog, but the scope change indicates that components beyond the originating context can be affected, raising the overall risk. The likely attack vector, based on inferential analysis, is that an attacker supplies a specially crafted path in a ColdFusion request to read or write unauthorized files.

Generated by OpenCVE AI on July 21, 2026 at 17:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Adobe ColdFusion to a version that includes the path traversal fix, following the guidance in Adobe's advisory.
  • Configure the ColdFusion application and web server to validate all file paths and enforce directory boundaries, ensuring that only intended directories are accessible.
  • Harden the file system permissions so that the ColdFusion service has write access only to authorized directories, limiting the potential damage from any remaining write capability.

Generated by OpenCVE AI on July 21, 2026 at 17:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 30 Jun 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe coldfusion
Vendors & Products Adobe
Adobe coldfusion

Tue, 30 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 16:00:00 +0000

Type Values Removed Values Added
Description ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read and limited write access. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.
Title ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Adobe Coldfusion
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-06-30T16:08:32.189Z

Reserved: 2026-05-21T15:28:38.136Z

Link: CVE-2026-48313

cve-icon Vulnrichment

Updated: 2026-06-30T16:07:14.001Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T18:00:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')