Junglewise Threat Intelligence

CVE-2026-27305: Adobe ColdFusion path traversal arbitrary file read

CVE-2026-27305 · Severity: high · CVSS 8.6 · Published 2026-04-14

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion, a platform for building enterprise web applications, is affected by a security flaw that allows unauthorized access to the server's file system. An attacker can exploit this to read sensitive configuration files, credentials, or other internal data without needing any user interaction. This could lead to a significant data breach or provide information necessary for further attacks on the organization's infrastructure.

Technical details

A path traversal vulnerability (CWE-22) exists in Adobe ColdFusion versions 2023.18, 2025.6, and earlier. The flaw stems from improper limitation of a pathname to a restricted directory, allowing an unauthenticated attacker to send specially crafted network requests to read arbitrary files on the host file system. The vulnerability has a CVSS score of 8.6, reflecting its high impact on confidentiality and the lack of required privileges or user interaction. Attackers can leverage this to bypass access controls and retrieve sensitive system information or application source code. Adobe has addressed this issue in security bulletin APSB26-38.

Affected products

  • Adobe ColdFusion 2023.18 and earlier, 2025.6 and earlier

Timeline

  • 2026-04-14: disclosed
  • 2026-04-14: advisory: Adobe published security bulletin APSB26-38

References

Related threats