Junglewise Threat Intelligence

CVE-2026-34619: Adobe ColdFusion path traversal security bypass

CVE-2026-34619 · Severity: high · CVSS 7.7 · Published 2026-04-14

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion, a platform for building and deploying web applications, is affected by a security flaw that allows unauthorized access to files. An attacker could bypass security restrictions to view or interact with sensitive files and directories that should be protected. This could lead to the exposure of internal system information or a disruption of services without requiring any action from a legitimate user.

Technical details

A path traversal vulnerability (CWE-22) exists in Adobe ColdFusion versions 2023.18, 2025.6 and earlier. The flaw stems from improper limitation of a pathname to a restricted directory, allowing an attacker to bypass security features. This is a network-based attack that requires low privileges (PR:L) but no user interaction. Successful exploitation enables an attacker to access files or directories outside of the intended web root or restricted areas. While the CVSS vector indicates a primary impact on availability (A:H) and a scope change (S:C), the vulnerability fundamentally allows for unauthorized file system navigation. Adobe has released security bulletin APSB26-38 to address this issue.

Affected products

  • Adobe ColdFusion 2023.18 and earlier, 2025.6 and earlier

Timeline

  • 2026-04-14: disclosed
  • 2026-04-14: advisory: Adobe security bulletin APSB26-38 published

References

Related threats