Description
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Published: 2026-07-13
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An uncontrolled search path element flaw (CWE‑427) exists in Adobe ColdFusion versions 2025.9, 2023.20 and earlier. The vulnerability allows a malicious file to be loaded when a user opens it, leading to the execution of arbitrary code with the privileges of the account running ColdFusion. The flaw is marked as a scope‑changing issue, meaning that the attack can affect higher‑privileged processes beyond the original context.

Affected Systems

Adobe ColdFusion servers running any version up to and including 2025.9, 2023.20, and earlier releases. The issue is not limited to a specific module but applies to the core ColdFusion runtime.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity level, and the EPSS score of <1% indicates a very low but measurable exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires user interaction: a victim must open a malicious file. Because the flaw has a scope change, the impact is elevated, but the attack must be initiated by the end‑user, limiting the attack surface. Nonetheless, any entity that receives malicious files through ColdFusion remains at high risk.

Generated by OpenCVE AI on July 31, 2026 at 11:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Adobe ColdFusion patch or upgrade to the latest supported release as detailed in the Adobe Security Advisory APSB26-68.
  • If an immediate patch is not feasible, restrict file access on the ColdFusion server, enforce strict file type validation, and block execution of untrusted files in the installation directories.
  • Educate users and administrators to avoid opening suspicious files and monitor ColdFusion logs for unusual file parsing activity.

Generated by OpenCVE AI on July 31, 2026 at 11:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe coldfusion
Vendors & Products Adobe
Adobe coldfusion

Mon, 13 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Title ColdFusion | Uncontrolled Search Path Element (CWE-427)
Weaknesses CWE-427
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Coldfusion
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T03:58:55.358Z

Reserved: 2026-05-21T15:28:38.141Z

Link: CVE-2026-48363

cve-icon Vulnrichment

Updated: 2026-07-14T13:51:08.362Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T11:30:05Z

Weaknesses
  • CWE-427

    Uncontrolled Search Path Element