Description
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Published: 2026-07-13
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an uncontrolled search path element that can allow an attacker to execute arbitrary code in the context of the user that opens a malicious file. The weakness is identified as CWE‑427 and it changes the scope of the vulnerability, allowing the execution to occur with the privileges of the user who interacts with the file. The description specifies that the attack requires user interaction: a victim must open a crafted file for the exploit to succeed.

Affected Systems

ColdFusion products from Adobe, specifically versions 2025.9, 2023.20 and all earlier releases. Any installation running the affected code base is vulnerable. The vulnerability applies to the ColdFusion runtime component that processes user‑supplied files.

Risk and Exploitability

The CVSS score of 8.2 classifies this as a high‑severity flaw. The EPSS score is 0.00158, indicating a very low but non‑zero probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be a user‑initiated action, such as opening a malicious attachment or accessing a specially crafted web resource. Because the flaw relies on user interaction, it is less likely to be exploited remotely, but the potential for arbitrary code execution with the victim’s privileges makes it a serious concern for environments where users have the ability to download or open files.

Generated by OpenCVE AI on July 31, 2026 at 11:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Adobe ColdFusion security update that addresses CVE-2026-48364 as soon as it becomes available.
  • Configure the application or underlying system to restrict the execution of unknown or untrusted file types, ensuring that only signed or otherwise verified files are processed.
  • Monitor file access and execution logs for unusual activity, and enforce strict user education on the risks of opening unsolicited files.

Generated by OpenCVE AI on July 31, 2026 at 11:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe coldfusion
Vendors & Products Adobe
Adobe coldfusion

Mon, 13 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Title ColdFusion | Uncontrolled Search Path Element (CWE-427)
Weaknesses CWE-427
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Coldfusion
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T03:58:56.154Z

Reserved: 2026-05-21T15:28:38.141Z

Link: CVE-2026-48364

cve-icon Vulnrichment

Updated: 2026-07-14T13:13:45.727Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T11:30:05Z

Weaknesses
  • CWE-427

    Uncontrolled Search Path Element