Executive brief
Adobe ColdFusion, a platform for building enterprise web applications, is affected by a security flaw that allows unauthorized access to files. An attacker could trick a user into opening a specially crafted file to bypass security restrictions and view or modify sensitive data on the server. This could lead to a total compromise of the application's data and availability.
Technical details
A path traversal vulnerability (CWE-22) exists in Adobe ColdFusion due to improper limitation of pathnames to restricted directories. The flaw allows an attacker to bypass security features and access files or directories outside of the intended scope. Exploitation requires an adjacent network position and user interaction, specifically requiring a victim to open a malicious file. Successful exploitation results in a changed scope (S:C) with high impact on confidentiality, integrity, and availability. Adobe has addressed this in security bulletin APSB26-64.
Affected products
- Adobe ColdFusion 2023.19 and earlier, 2025.8 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory: Adobe security bulletin APSB26-64 published