Executive brief
Adobe ColdFusion, a platform for building and deploying web applications, is affected by a security flaw that could allow an attacker to read private files from the server. To exploit this, an attacker must trick a user into opening a specially crafted malicious file. This could result in the exposure of sensitive configuration data or internal system information, potentially leading to further unauthorized access.
Technical details
An XML External Entity (XXE) vulnerability (CWE-611) exists in Adobe ColdFusion due to improper restriction of XML external entity references. The flaw allows a remote attacker to read arbitrary files from the server's file system by inducing a user to process a malicious XML-based file. The vulnerability is assigned a CVSS score of 7.4, reflecting a high confidentiality impact with a requirement for user interaction (UI:R) and a changed scope (S:C). Affected versions include ColdFusion 2023 update 19 and earlier, and ColdFusion 2025 update 8 and earlier. Users are advised to apply the security updates provided by Adobe in bulletin APSB26-64.
Affected products
- Adobe ColdFusion 2023.19 and earlier, 2025.8 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory: Adobe security bulletin APSB26-64 published