Description
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-07-14
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory vulnerability that permits reading arbitrary files outside the intended directory. The flaw can expose sensitive data and log files and does not require user interaction, meaning an attacker can trigger it remotely. The CVSS base score of 6.8 indicates a moderate severity with scope changed, giving the attacker the ability to affect the entire system.

Affected Systems

The vulnerability applies to Adobe ColdFusion 2023 and Adobe ColdFusion 2025 releases. Any installation of these products that has not yet applied the vendor’s patch is at risk.

Risk and Exploitability

With a CVSS score of 6.8 the risk is moderate but still critical for protecting data confidentiality. The EPSS score of less than 1% shows a low the vulnerability is not currently listed in CISA KEV. Likely attack vectors are remote over the web interface, as the flaw is triggered by crafted URLs or requests that contain path traversal sequences. However, the official description does not specify the exact network surface, so the assessment infers a typical HTTP‑based exploitation path.

Generated by OpenCVE AI on July 31, 2026 at 04:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe ColdFusion patch that fixes CVE-2026 so that the web server’s document root does not expose sensitive directories and enforce strict directory limits.
  • Deploy web application firewall rules that detect and block path traversal patterns in incoming requests.
  • Configure network access controls to restrict inbound traffic to the ColdFusion application server to trusted IP ranges.

Generated by OpenCVE AI on July 31, 2026 at 04:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025
Vendors & Products Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025

Thu, 16 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.
Title ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Adobe Coldfusion 2023 Coldfusion 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-16T15:01:16.864Z

Reserved: 2026-05-21T15:28:38.139Z

Link: CVE-2026-48338

cve-icon Vulnrichment

Updated: 2026-07-16T15:01:08.903Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T04:45:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')