Description
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-07-14
Score: 9.1 Critical
EPSS: 32.3% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The reported flaw in ColdFusion is an improper limitation of a pathname to a restricted directory, also known as a path traversal vulnerability. This weakness allows an attacker to reference files and directories outside the intended storage area, enabling an attacker to exploit resources under which the ColdFusion application is running. Because the vulnerability can fully compromise the availability, confidentiality and integrity of the affected system. This flaw is classified as CWE‑22.

Affected Systems

Adobe ColdFusion 2023 and ColdFusion 2025 are identified as affected by the CNA. Specific version numbers are not listed, so all current releases of those product lines should be considered vulnerable until an advisory confirms otherwise.

Risk and Exploitability

The CVSS base score of 9.1 reflects the severity of arbitrary code execution. The EPSS score of 32% indicates that the likelihood of exploitation in the wild is moderately high, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote HTTP request to the ColdFusion server; this inference is drawn from the fact that no user interaction is required. Once path traversal succeeds, the attacker can change the effective execution scope, potentially affecting the entire system running the ColdFusion service.

Generated by OpenCVE AI on August 1, 2026 at 09:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Adobe ColdFusion 2023 and ColdFusion 2025 to the latest release that contains the fix for the path traversal flaw.
  • Restrict or lock down the ColdFusion administrator interface and any file upload endpoints to trusted IP ranges or remove them from public exposure.
  • Implement monitoring of web server logs for anomalous path traversal attempts and block any requests that include traversal patterns.

Generated by OpenCVE AI on August 1, 2026 at 09:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025
Vendors & Products Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025

Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Title ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Coldfusion 2023 Coldfusion 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-21T21:19:01.997Z

Reserved: 2026-05-21T15:28:38.137Z

Link: CVE-2026-48319

cve-icon Vulnrichment

Updated: 2026-07-15T10:33:38.125Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:15:03Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')